I need to set up a Splunk forwarder to send /var/log/messages and /var/log/secure (with add monitor )from a machine to our main Splunk server but also send monitored files from another directory on this same server to a separete, specific Splunk server with sourcetype cisco_esa.
Can this be done by configuring inputs.conf and outputs.conf on a single Universal forwarder?
I've been able to get the individual tasks accomplished. And I'm considering running 2 instances of Universal forwarder. Just wondering if this can be done with one.
... View more