I would say this partly covers shipping systemd journal logs to splunk. What I would really love is for splunk to be able to accept data sent by systemd-journal-upload ( https://www.freedesktop.org/software/systemd/man/latest/systemd-journal-upload.service.html ). That way you'd not need a forwarder on any popular systemd distribution anymore. You could just use systemd.
... View more