Hi..
I was used to using splunk as a single instance in my laptop. I am new to forwarders and indexes. I have log data in the form of csv files available(with headers) . Assuming data is in /abc/data_files and splunk forwarder files are in /abc/splunkforwarder/etc/system/local.
In the local I only find these files
deploymentclient.conf, inputs.conf, outputs.conf, README, server.conf.
When I opened inputs.conf and outputs.conf I found them to be empty.
I do not know if I am even in the right direction in wanting to make changes in the forwarder. I am really lost. Please consider me to be a beginner. Please let me step by step or point me to a document to figure out how to do this?
These should help you get started
Distributed Splunk Architecture: http://docs.splunk.com/Documentation/Splunk/6.2.2/Deploy/Distributedoverview
Indexer configuration
Index Creation: http://docs.splunk.com/Documentation/Splunk/6.2.2/Indexer/Setupmultipleindexes
Props entries/sourcetype definition: http://docs.splunk.com/Documentation/Splunk/6.2.2/Data/Createsourcetypes
Forwarder configuration
Outputs.conf: http://docs.splunk.com/Documentation/Splunk/6.2.2/Forwarding/Configureforwarderswithoutputs.confd
Inputs.conf: http://docs.splunk.com/Documentation/Splunk/6.2.2/Data/Editinputs.conf
These should help you get started
Distributed Splunk Architecture: http://docs.splunk.com/Documentation/Splunk/6.2.2/Deploy/Distributedoverview
Indexer configuration
Index Creation: http://docs.splunk.com/Documentation/Splunk/6.2.2/Indexer/Setupmultipleindexes
Props entries/sourcetype definition: http://docs.splunk.com/Documentation/Splunk/6.2.2/Data/Createsourcetypes
Forwarder configuration
Outputs.conf: http://docs.splunk.com/Documentation/Splunk/6.2.2/Forwarding/Configureforwarderswithoutputs.confd
Inputs.conf: http://docs.splunk.com/Documentation/Splunk/6.2.2/Data/Editinputs.conf