Thanks....I will check it..
Not Helpful.
I installed on Splunk Oracle Add on UF and configured inputs.conf. But how should splunk forwader should transfer logs to indexer?
Very easily ... by configuring your SplunkForwarder to send it to your Indexer 🙂
Assuming that your SplunkForwarder is installed in /opt/splunkforwarder, edit/create the following file:
/opt/splunkforwarder/etc/system/local/outputs.conf:
[tcpout]
defaultGroup = your_splunk_index_group
disabled = 0
[tcpout:your_splunk_index_group]
server = FQDN_of_your_indexer:9997
disabled = 0
maxQueueSize = 500MB
useACK = true