Getting Data In

Can the logging location of a 'NIX Universal Forwarder be changed?

craigscherer
Engager

I want the UF's logging to be in /var/log/splunk not subordinate to $SPLUNK_HOME is there a Splunk UF parameter that can accomplish this. I would rather not have to track a soft link (ln -s).

Tags (1)

Ayn
Legend

The path Splunk should be logging to is set in a number of places in the file $SPLUNK_HOME/etc/log.cfg, for instance:

appender.A1.fileName=${SPLUNK_HOME}/var/log/splunk/splunkd.log

...and so on. Change these to wherever you want Splunk to write its own logs.

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...