Getting Data In

Using a shell script to collect data on a universal forwarder, what do I need to configure in inputs and outputs.conf?

athorat
Communicator

Universal Forwarder-> Heavy Forwarder -> Indexer
We have a universal forwarder which is sitting on a different domain from where we want to collect data using a shell script.

Using the UI, I uploaded the shell script on the universal forwarder. How do I configure what data to send to the indexer?
As I have uploaded the shell using UI on the universal forwarder, do I need to configure the inputs.conf again?
What would be the settings/parameters on both the inputs.conf on the UF and HF
and also the outputs.conf?

0 Karma

FritzWittwer_ol
Contributor

You have to configure inputs.conf,

[script://<script>] 
interval=60

60 seconds is the default value for interval, and you can use the usual attributes like index, sourcetype, disabled.

see http://docs.splunk.com/Documentation/Splunk/6.2.5/Data/Setupcustominputs

Get Updates on the Splunk Community!

Holistic Visibility and Effective Alerting Across IT and OT Assets

Instead of effective and unified solutions, they’re left with tool fatigue, disjointed alerts and siloed ...

SOC Modernization: How Automation and Splunk SOAR are Shaping the Next-Gen Security ...

Security automation is no longer a luxury but a necessity. Join us to learn how Splunk ES and SOAR empower ...

Ask It, Fix It: Faster Investigations with AI Assistant in Observability Cloud

  Join us in this Tech Talk and learn about the recently launched AI Assistant in Observability Cloud. With ...