Getting Data In

What configurations would be made to inputs.conf in order to have the same log file be monitored on all my servers?

kranthimutyala
Path Finder

I have 64 servers and I need to monitor the same log file on all the 64 servers. What would be the inputs.conf file configuration for this setup or any solution for this kind of requirement?

0 Karma

paulstout
Path Finder

From my understanding and assuming the file is in the same location, inputs.conf does not need any special treatment. I presume you're using a deployment server so you'll want to create an app containing the inputs.conf, define a serverclass for the 64 machines, then add a stanza to push that app to the defined serverclass.

0 Karma

kranthimutyala
Path Finder

can u give me the rough example of each file

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@kranthimutyala - Did the answer provided by paulstout help provide a working solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!

0 Karma

paulstout
Path Finder

This documentation page covers everything you need (in far more depth than I could rattle off): http://docs.splunk.com/Documentation/Splunk/6.5.2/Updating/Aboutdeploymentserver

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Maximizing the Value of Splunk ES 8.x

Splunk Enterprise Security (ES) continues to be a leader in the Gartner Magic Quadrant, reflecting its pivotal ...