Getting Data In

add log file to splunk universal forwarder

jszyba
New Member

I'm trying to monitor a log file to a splunk universal forwarder. For example the splunkd.log file. I've tried getting into the inputs.conf file on the machine with the universal forwarder intstalled and adding [monitor://$SPLUNK_HOME\var\log\splunk\splunkd.log]. I can't see the log file on the main reciever. What am I missing here? Please help....

Tags (3)
0 Karma

rkirkw
Path Finder

The splunkd.log is most likely already being sent by the forwarder but you may not be searching the internal indexes by default.

Try this search:
index=_internal source="/opt/splunkforwarder/var/log/splunk/splunkd.log" host=hostname

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

That file should be monitored automatically, search the _internal index for it.

0 Karma
Get Updates on the Splunk Community!

Check out this month’s brand new Splunk Lantern articles

Splunk Lantern is a customer success center providing advice from Splunk experts on valuable data insights, ...

Happy CX Day to our Community Superheroes!

Happy 10th Birthday CX Day!What is CX Day? It’s a global celebration recognizing innovation and success in the ...

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...