Getting Data In

Universal Forwarder Log DIR

Josh
Path Finder

Is it possible to configure the log directory of a Windows 4.2 unviversal fowarder?

i.e. we want to log to a directory which is not C:/Program Files/Splunk/var/log/splunk to meet our environment policies.

Tags (1)
1 Solution

Rob
Splunk Employee
Splunk Employee

Hi Josh,

You may want to create a log-local.cfg file in $SPLUNK_HOME/etc/ which includes a custom path for the following log configuration setting:

appender.A1.fileName=/path/to/your/custom/file.log

For more information, the following documentation link has some useful configuration settings for your log files.

http://www.splunk.com/base/Documentation/4.2/Admin/SplunkLogFiles#log.cfg

View solution in original post

Rob
Splunk Employee
Splunk Employee

Hi Josh,

You may want to create a log-local.cfg file in $SPLUNK_HOME/etc/ which includes a custom path for the following log configuration setting:

appender.A1.fileName=/path/to/your/custom/file.log

For more information, the following documentation link has some useful configuration settings for your log files.

http://www.splunk.com/base/Documentation/4.2/Admin/SplunkLogFiles#log.cfg

Get Updates on the Splunk Community!

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...