How to collect the different types of logs form different types of applications? All the applications were residing in a single server
with a single universal forwarder or do we need to configure anything.
Without more specific info on how those applications write/send their logs, it is a bit hard to give any specific answer.
But basically I would say you can for instance create a separate inputs.conf stanza for each application, pointing it to the relevant log directory and setting individual index and sourcetype settings as desired.
Without more specific info on how those applications write/send their logs, it is a bit hard to give any specific answer.
But basically I would say you can for instance create a separate inputs.conf stanza for each application, pointing it to the relevant log directory and setting individual index and sourcetype settings as desired.