I have Splunk Universal Forwarder installed on raspberry pi and couple of apps from which I want to send logs to forwarder. What is the best and most efficient way to do this? I was thinking of:
Http event collector
Monitor local directories where apps are storing their logs in json format (large files)
I cannot use tcp because there is no .net core library for this purpose
Also, target Splunk instance to which forwarder sends data, is often offline, so fowarder needs to buffer big amount of logs. That's why I thought that monitoring files will be the best approach here but i'm not sure.
... View more