Getting Data In

Can the logging location of a 'NIX Universal Forwarder be changed?

craigscherer
Engager

I want the UF's logging to be in /var/log/splunk not subordinate to $SPLUNK_HOME is there a Splunk UF parameter that can accomplish this. I would rather not have to track a soft link (ln -s).

Tags (1)

Ayn
Legend

The path Splunk should be logging to is set in a number of places in the file $SPLUNK_HOME/etc/log.cfg, for instance:

appender.A1.fileName=${SPLUNK_HOME}/var/log/splunk/splunkd.log

...and so on. Change these to wherever you want Splunk to write its own logs.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...