I'm brand new to this and am hopeful this has a ready-made answer I've not been able to find (yet) but: We installed the universal forwarder from our Splunk Cloud instructions: Set up the .spl file and added a monitor to a log4j folder of a software that server runs. How we set this up on our non-Windows systems is with indexer tokens that are used at setup. In my case with this windows system, the installation and set up goes fine. I don't see any errors in the splunkd.log on the host machine. But there's no data for that index. How do I add the specific index token to the universal forwarder?
... View more