Hi
Anyone know how to change the default log location of splunk logs in splunk indexer and universal forwarder please?
At the moment splunk indexer and forwarder is writing under /opt I want to move it to /var
Thanks
The main logging config file resides at $SPLUNK_HOME/etc/log.cfg
Further details can be found here : http://docs.splunk.com/Documentation/Splunk/5.0/Troubleshooting/WhatSplunklogsaboutitself
The main logging config file resides at $SPLUNK_HOME/etc/log.cfg
Further details can be found here : http://docs.splunk.com/Documentation/Splunk/5.0/Troubleshooting/WhatSplunklogsaboutitself
Great , if this works for you then please accept the answer 🙂
Thanks for that.....I had a look at the file and I believe I can change the path directly