Getting Data In

Universal Forwarder for OSX installed - how is it configured ?

eyeLikeCarrots
New Member

Hello All,

I have the OSX Universal Forwarder installed on a 10.5 machine and Splunk installed on a server successfully receiving events from two Windows machines.

How do I configure the OSX Forwarder to:

  • Nominate the log files I want monitored.
  • Set the IP address of the server that the Forwarder will send event data too.

I cannot find this specific information in the documentation.

Cheers

Tags (1)
0 Karma

lguinn2
Legend

You need to create the following files:

inputs.conf - to identify the files to be monitored

See http://docs.splunk.com/Documentation/Splunk/latest/Data/Editinputs.conf for help. You may also need props.conf, but it depends on your inputs. Here is an example that monitors a single syslog log file:

[monitor:///logs/mylogfile.log]
sourcetype=syslog
host=yourOSXhostname

outputs.conf - to tell Splunk where to forward the data. Example:

[tcpout:my_indexer]
server=10.10.10.1:9997

Note that you have to supply the server ip (or dns name) and the port number where Splunk is listening for forwarded data. See http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configureforwarderswithoutputs.confd for more info and options.

Put the files in "/Applications/splunkforwarder/etc/system/local" or your equivalent.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...