I have 64 servers and I need to monitor the same log file on all the 64 servers. What would be the inputs.conf file configuration for this setup or any solution for this kind of requirement?
From my understanding and assuming the file is in the same location, inputs.conf does not need any special treatment. I presume you're using a deployment server so you'll want to create an app containing the inputs.conf, define a serverclass for the 64 machines, then add a stanza to push that app to the defined serverclass.
can u give me the rough example of each file
@kranthimutyala - Did the answer provided by paulstout help provide a working solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!
This documentation page covers everything you need (in far more depth than I could rattle off): http://docs.splunk.com/Documentation/Splunk/6.5.2/Updating/Aboutdeploymentserver