Getting Data In

Can the logging location of a 'NIX Universal Forwarder be changed?

craigscherer
Engager

I want the UF's logging to be in /var/log/splunk not subordinate to $SPLUNK_HOME is there a Splunk UF parameter that can accomplish this. I would rather not have to track a soft link (ln -s).

Tags (1)

Ayn
Legend

The path Splunk should be logging to is set in a number of places in the file $SPLUNK_HOME/etc/log.cfg, for instance:

appender.A1.fileName=${SPLUNK_HOME}/var/log/splunk/splunkd.log

...and so on. Change these to wherever you want Splunk to write its own logs.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...