Hello all,
I have somme issue with my universal forwarder and I would like to monitor the logs file of my forwader (metrics.log, splunkd.log, ...) from the indexer to see what's wrong.
Is there a way in a outputs.conf to forward this logs file to the indexer ? Or we need to put [monitor:///opt/splunk/var/log/splunk/metrics*] and [monitor:///opt/splunk/var/log/splunk/splunkd*] on the inputs.conf file.
Thanks a lot
LudoZ
Using the inputs.conf on the forwarder side sounds like a good option.
You should, push it to a specific index so that it doesn't fall into the main one.
Make sure that you put index=_internal in your search if you are trying to query the splunkd.log files. I could not see mine even signed on as admin and starting the search with index="*"
Using the inputs.conf on the forwarder side sounds like a good option.
You should, push it to a specific index so that it doesn't fall into the main one.