Hi all,
I am trying to set up ansible playbook for splunk forwarder. Though github completely doesnot help. Has anyone automated it? If i want to add logs for monitoring with multiple source types and with different logs? how can i do this:
for ex:
name: add temporary monitor to create directory
command: "{{ splunkhome }} add monitor {{ item }} -sourcetype syslog -auth {{ splunkcreds }}"
with_items:
- /var/log/syslog
notify: restart_splunk
how can i use multiple logs and for each logs each source type is necessary? Any suggestions ?
... View more