I want to monitor /var/log on all of my Splunk Indexers. However, when I configured this, I was then getting issues connecting to my Heavy Forwarders. I configured an outputs.conf to send the logs to the Heavy Forwarders, then back to the Indexers. This probably doesn't sound right.
How would this be accomplished?
Thanks!
P.S. How would I monitor the /var/log on my Heavy Forwards, Search Heads, etc?
I think I have it working by not specifying any outputs.conf on the Indexers.
I think I have it working by not specifying any outputs.conf on the Indexers.
I think I have it working by not specifying any outputs.conf on the Indexers.