Getting Data In

Using a shell script to collect data on a universal forwarder, what do I need to configure in inputs and outputs.conf?

athorat
Communicator

Universal Forwarder-> Heavy Forwarder -> Indexer
We have a universal forwarder which is sitting on a different domain from where we want to collect data using a shell script.

Using the UI, I uploaded the shell script on the universal forwarder. How do I configure what data to send to the indexer?
As I have uploaded the shell using UI on the universal forwarder, do I need to configure the inputs.conf again?
What would be the settings/parameters on both the inputs.conf on the UF and HF
and also the outputs.conf?

0 Karma

FritzWittwer_ol
Contributor

You have to configure inputs.conf,

[script://<script>] 
interval=60

60 seconds is the default value for interval, and you can use the usual attributes like index, sourcetype, disabled.

see http://docs.splunk.com/Documentation/Splunk/6.2.5/Data/Setupcustominputs

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...