Splunk Enterprise

Universal forwarder - configuration

verifi81
Path Finder

Hello,

On a Universal Forwarder can someone tell me where the config is that tells the universal forwarder where to send the logs?

I need this for Windows and Linux.

Thank you

Labels (1)
0 Karma
1 Solution

verifi81
Path Finder

I found it. 

It's under $SPLUNK_HOME/etc/apps/search/local/

The file is outputs.conf

 

View solution in original post

0 Karma

vikramyadav
Contributor

I'm not sure which log file you are interested in so you can use btool to check outputs.conf

For Linux and Linux

$Splunk_Home/splunk btool outputs list --debug

 

-------------------------------------

If this help your like will be appreciated 🙂

 

0 Karma

verifi81
Path Finder

appreciate the quick response, but that video and blog did not tell me which file to view those settings at. My universal forwarders are already forwarding to an index and I'm simply trying to find which file I can CAT to view the indexer.  

0 Karma

vikramyadav
Contributor
0 Karma

verifi81
Path Finder

I found it. 

It's under $SPLUNK_HOME/etc/apps/search/local/

The file is outputs.conf

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...