Getting Data In

In what path/directory do you find forwarded data from a universal forwarder on the Splunk indexer?

05500
New Member

When we use universal forwarder, do you know where forwarded data is on the Splunk server?
Could you please tell me which path/directory for forwarded data?

0 Karma
1 Solution

kml_uvce
Builder

When you use universal forwarder then it reads data from files, script etc in inputs.conf file http://docs.splunk.com/Documentation/Splunk/6.2.2/Admin/inputsconf
and it sends data to indexer given in outputs.conf file
http://docs.splunk.com/Documentation/Splunk/6.2.2/Admin/Outputsconf

data in indexer is stored in indexes in location $SPLUNK_HOME/var/lib/splunk in indexer
http://docs.splunk.com/Documentation/Splunk/6.2.2/Admin/Splunk-launchconf

View solution in original post

kml_uvce
Builder

When you use universal forwarder then it reads data from files, script etc in inputs.conf file http://docs.splunk.com/Documentation/Splunk/6.2.2/Admin/inputsconf
and it sends data to indexer given in outputs.conf file
http://docs.splunk.com/Documentation/Splunk/6.2.2/Admin/Outputsconf

data in indexer is stored in indexes in location $SPLUNK_HOME/var/lib/splunk in indexer
http://docs.splunk.com/Documentation/Splunk/6.2.2/Admin/Splunk-launchconf

Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...