I want the UF's logging to be in /var/log/splunk not subordinate to $SPLUNK_HOME is there a Splunk UF parameter that can accomplish this. I would rather not have to track a soft link (ln -s).
The path Splunk should be logging to is set in a number of places in the file $SPLUNK_HOME/etc/log.cfg
, for instance:
appender.A1.fileName=${SPLUNK_HOME}/var/log/splunk/splunkd.log
...and so on. Change these to wherever you want Splunk to write its own logs.