I need to set up a Splunk forwarder to send /var/log/messages and /var/log/secure (with add monitor
Can this be done by configuring inputs.conf and outputs.conf on a single Universal forwarder?
I've been able to get the individual tasks accomplished. And I'm considering running 2 instances of Universal forwarder. Just wondering if this can be done with one.
In inputs.conf you can use the _TCP_ROUTING property to target different forwarding groups in outputs.conf for the different sourcetypes being monitored.