Monitoring Splunk

Forwarding search head logs to indexer

aoliullah
Path Finder

Hi. I have been trying to forward my search head logs to the indexer as it is a best practice. In order to do so, I tried to create an outputs.conf under search app with all the parameters. However, I wanted to try out how it can be done through the GUI, so used the "configure forwarding" option and set the IP:destport. I now receive the internal logs.

However, I am trying to find out where that GUI setting would have got written to. It should technically have created a new outputs.conf file right? Could anyone tell me where it would reside please? I have tried to use the "locate" command on my search head box to find all the outputs.conf file but couldn't find the config written to any of them.

Thanks in advance!

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi aoliullah,
usually it's in $SPLUNK_HOME/etc/system/local.
everyway, you can find it also using btool command

./splunk cmd btool outputs list --debug

Bye.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi aoliullah,
usually it's in $SPLUNK_HOME/etc/system/local.
everyway, you can find it also using btool command

./splunk cmd btool outputs list --debug

Bye.
Giuseppe

0 Karma

aoliullah
Path Finder

Thank you.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...