Getting Data In

Will LWF's metrics.log be forwarded to the Indexer as default?

Masa
Splunk Employee
Splunk Employee

I've noticed LWF's metrics.log were forwarded to the indexer as default in some version of splunk. But, not all the versions. So, which version of LWF will send metrics.log to the Indexer(s)?

Tags (3)

Masa
Splunk Employee
Splunk Employee

(Corrected the list.) I checked the following versions' default inputs.conf. Here is the list;

4.0.11: Forwarded
4.1.2 : Forwarded
4.1.3 : Forwarded
4.1.4 : Forwarded
4.1.5 : Not Forwarded
4.1.6 : Not Forwarded
4.1.7 : Not Forwarded
4.2 : Forwarded
4.2UniversalForwarder: Forwarded

This is just a default. Of course, you can change the behavior to turn on/off by configuring an inputs.conf.

Masa
Splunk Employee
Splunk Employee

Gerald: Sorry but my first list was wrong... So, I corrected. It's kinda consistent...or not.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Thank you! This inconsistency is maddening.

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...