Getting Data In

What are some best practices for Splunk universal forwarder?


My Splunk Forwarder inputs.conf looks like this:

index = myapi_local
move_policy = sinkhole
disabled = 0
source = myapi
sourcetype = Api


My logging files are generating every second . Is that perhaps a little bit too excessive? What's the best practice in using the Forwarder?

File name examples:

MyAPI_2022-12-08 23-06-28.json

MyAPI_2022-12-08 23-06-29.json


Thanks! 🙂

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...

Security Newsletter Updates | March 2023

 March 2023 | Check out the latest and greatestUnify Your Security Operations with Splunk Mission Control The ...