Getting Data In

Universal Forwarder - Add another Log FIle to Index

pgergen
New Member

Hi

I have a Linux Splunk Indexer.

How do I add another log file to be indexed by Splunk to the Universal Forwarder on a Windows Server ?

Many Thanks

Regards
Peta Gergen
peta.gergen@team.telstra.com

0 Karma

lalit_mohan
Path Finder

Hi Guys,

I have similar problem!!!

I have two instances one is splunk-server and other is splunk-forwarder(universalForwarder).
Everything is fine with configuration ,then I tried to monitor tomcat logs and I have perform below steps on forwarder.

/usr/share/splunk_setup/splunkforwarder/bin/splunk add monitor /usr/share/apache-tomcat-7.0.42/logs/catalina.out -index default -sourcetype log4j -hostname splunkforwarder

But in search tab of splunk-web I always get No results found.

Am I missing something !!!.Please help me out.
Thanks in advance!!

0 Karma

Ayn
Legend

There's a whole manual covering these topics in the docs. This should be a good place to start: http://docs.splunk.com/Documentation/Splunk/latest/Data/Configureyourinputs

Long story short: either use the CLI or add a directive in in an inputs.conf file (for instance in $SPLUNK_HOME/etc/system/local).

CLI: $SPLUNK_HOME/bin/splunk add monitor <logdir>

inputs.conf: [monitor:///<logdir>]

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...