Getting Data In

Universal Forwarder Log DIR

Josh
Path Finder

Is it possible to configure the log directory of a Windows 4.2 unviversal fowarder?

i.e. we want to log to a directory which is not C:/Program Files/Splunk/var/log/splunk to meet our environment policies.

Tags (1)
1 Solution

Rob
Splunk Employee
Splunk Employee

Hi Josh,

You may want to create a log-local.cfg file in $SPLUNK_HOME/etc/ which includes a custom path for the following log configuration setting:

appender.A1.fileName=/path/to/your/custom/file.log

For more information, the following documentation link has some useful configuration settings for your log files.

http://www.splunk.com/base/Documentation/4.2/Admin/SplunkLogFiles#log.cfg

View solution in original post

Rob
Splunk Employee
Splunk Employee

Hi Josh,

You may want to create a log-local.cfg file in $SPLUNK_HOME/etc/ which includes a custom path for the following log configuration setting:

appender.A1.fileName=/path/to/your/custom/file.log

For more information, the following documentation link has some useful configuration settings for your log files.

http://www.splunk.com/base/Documentation/4.2/Admin/SplunkLogFiles#log.cfg

Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...