Getting Data In

What configurations would be made to inputs.conf in order to have the same log file be monitored on all my servers?

kranthimutyala
Path Finder

I have 64 servers and I need to monitor the same log file on all the 64 servers. What would be the inputs.conf file configuration for this setup or any solution for this kind of requirement?

0 Karma

paulstout
Path Finder

From my understanding and assuming the file is in the same location, inputs.conf does not need any special treatment. I presume you're using a deployment server so you'll want to create an app containing the inputs.conf, define a serverclass for the 64 machines, then add a stanza to push that app to the defined serverclass.

0 Karma

kranthimutyala
Path Finder

can u give me the rough example of each file

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@kranthimutyala - Did the answer provided by paulstout help provide a working solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!

0 Karma

paulstout
Path Finder

This documentation page covers everything you need (in far more depth than I could rattle off): http://docs.splunk.com/Documentation/Splunk/6.5.2/Updating/Aboutdeploymentserver

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...