Getting Data In

Cluster Master Send Internal Logs To Indexer

Ne_phil
Loves-to-Learn Lots

Hi Splunk Community --

I'm trying to ensure that my cluster master is sending internal logs to the indexer. Which directory in my cluster master should I put outputs. conf? And are there other conf files that should accompany my outputs.conf file?

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Ne_phil,

Why shoud you use an outputs.conf to send Master Node's logs to indexers?

it's a single machine, you can easily configure forwarding by GUI [Settings > Forwardring and Receiving > Forwardring] and Splunk will send all logs, without thinking to which folders having to monitor.

Ciao.

Giuseppe

 

0 Karma

Ne_phil
Loves-to-Learn Lots

in our environment our cluster master (master node) and indexers (peer nodes) are all on separate servers and we are trying to set it up from backend instead of the GUI.

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Ho @Ne_phil 

as a best pratcice create app in location $SPLUNK_HOME/etc/apps/ 

ex: clm_forwarder_outputs--->local--->outputs.conf 

add indexer ips and restart splunk

0 Karma

Ne_phil
Loves-to-Learn Lots

I’m not following the example but placing the app in$SPLUNK_HOME/etc/apps makes sense.

But why not just put the outputs.conf in $SPLUNK_HOME/etc/system/local?

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @Ne_phil 
even $SPLUNK_HOME/etc/system/local location 

also works,  but from etc/apps/ it can be managed globally if you place it etc/apps/.

either ways its works

0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...