Is it possible to configure the log directory of a Windows 4.2 unviversal fowarder?
i.e. we want to log to a directory which is not C:/Program Files/Splunk/var/log/splunk to meet our environment policies.
You may want to create a log-local.cfg file in $SPLUNK_HOME/etc/ which includes a custom path for the following log configuration setting:
For more information, the following documentation link has some useful configuration settings for your log files.
View solution in original post