Hi,
On Linux Splunk servers, my system admin set this record in remotesyslog.conf
. @@syslog-zone40.uth.tmc.edu:1514
Anyone knows what type of logs this setup is send to Splunk HF? (os log and application log, or anything else)
Thank you,
Hi
Probably same events are sent also to local /var/log/messages and other files under /var/log directory? You should start to look there.
Ismo