Splunk Enterprise

How to collect different types of log data from different applications, residing in a single server?

raj_mpl
Path Finder

How to collect the different types of logs form different types of applications? All the applications were residing in a single server
with a single universal forwarder or do we need to configure anything.

Tags (1)
0 Karma
1 Solution

FrankVl
Ultra Champion

Without more specific info on how those applications write/send their logs, it is a bit hard to give any specific answer.

But basically I would say you can for instance create a separate inputs.conf stanza for each application, pointing it to the relevant log directory and setting individual index and sourcetype settings as desired.

View solution in original post

0 Karma

FrankVl
Ultra Champion

Without more specific info on how those applications write/send their logs, it is a bit hard to give any specific answer.

But basically I would say you can for instance create a separate inputs.conf stanza for each application, pointing it to the relevant log directory and setting individual index and sourcetype settings as desired.

View solution in original post

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!