Hello,
I'm Running Splunk with Modsecurity on a box running Apache and Modsecurity.
Do I have to use a forwarder? Or can I use "Data input" or some other setting
To import the data into the module. Directly from the filesystem?
It just seems a bit weird to send it someplace else and then back again! Tell me it's not so.
Cheers,
Dylan
Yes, absolutely, you can index from the local system. Look at the monitor: keyword in inputs.conf.