I've changed the outputs.conf file on my Universal Forwarder to direct to a different server, and restarted the service. However, I am still receiving the same data on the old server, and nothing on the new server. Am I changing the wrong file? It's in $SPLUNK_HOME\etc\system\local
.
Hi,
Can you please check from which outputs.conf your universal forwarder is taking configuration?
Use below command on universal forwarder, it will display the result, from which file your parameter for outputs.conf is taking value.
$SPLUNK_HOME/bin/splunk cmd btool outputs --debug list
Thanks,
Harshil
I did this, and the new server is listed as the tcp-out. However, it isn't receiving anything yet, and my old server is still constantly getting new data.