...retrained source types I see a few callouts for log files such as syslog but the majority of log files are not present in this list. Perhaps some of these types can be used elsewhere though? For example, I...
On my Linux server the universal forwarder and Splunk_TA_nix are installed, at least df and cpu are enabled in inputs.conf. vi /opt/splunkforwarder/etc/apps/Splunk_TA_nix/local/inputs.conf [s...
Discarding Specific typeof traffic either on forwarder or indexer fails, I tried to discard it using blacklist on forwarder and nullqueue transform on indexer and both failed.
here is a log s...
Hi All,
I'm presently forwarding a number of different events to a receiver. It's working fine for complete events, (i.e 4729, 4728 etc.) but I would like to be able to forward on Both the E...
Hi,
i'm new to splunk , i just wounder what is the difference between override source type/index from forwarder and from indexer???
and also if i choose to override sourcetype of files in u...
Now this could be a case of RTFM, but I can't find this in TFM 🙂
I am trying to find some documentation on what the Universal Forwarder does when it can't connect to an indexer for various s...
Universal Forwarder installed on a Windows server using all default settings. Where can I find the stanza that has the typesof events it is logging so that I can validate it received th
I am building a new Splunk environment, and due to the number of clients we have, we are building a simple distributed environment that consists of 1 Heavy Forwarder, universal forwarders all p...
...This data is then forwarded to one of the Indexers which does the indexing.
So far everything seems to be working, but for a few questions regarding the source type:
in inputs.conf in the e...
Hello,
I tested Splunk Light Trial version and this trial version is on Cloud service.
So I don't have a choice, I have to download the Universal Forwarder Credentials to configure the u...