Hi Team,
I have installed Splunk setup on one of my VM. On another VM I installed the Splunk universal forwarder to send the logs to Splunk Server.
I copied to make changes for inputs.conf and outputs.conf files to local folder to make changes because on default folder we shouldn't do changes.
So, they were so many attributes to make changes in both files. I am in confusion state.
Please tell me the basic values like where to insert host , source, sourcetype names, monitor file names, index name, etc in inputs.conf and where to give Splunk Server or Indexer IP, port number in outputs.conf.
Because i am setting up my test environment so that I wont do mistakes in my production environment .
Thanks & Regards,
Ravi
Steps should be like this
Configure Receiver (if not already done) https://docs.splunk.com/Documentation/Forwarder/6.6.1/Forwarder/Enableareceiver
Configure Forwarding
http://docs.splunk.com/Documentation/Forwarder/6.5.2/Forwarder/Configureforwardingwithoutputs.conf
Configure Data inputs. THis step generally have a pre-requisite of configuring event processing (http://docs.splunk.com/Documentation/Splunk/6.6.1/Data/Overviewofeventprocessing)
http://docs.splunk.com/Documentation/Splunk/6.6.1/Data/Configureyourinputs
Steps should be like this
Configure Receiver (if not already done) https://docs.splunk.com/Documentation/Forwarder/6.6.1/Forwarder/Enableareceiver
Configure Forwarding
http://docs.splunk.com/Documentation/Forwarder/6.5.2/Forwarder/Configureforwardingwithoutputs.conf
Configure Data inputs. THis step generally have a pre-requisite of configuring event processing (http://docs.splunk.com/Documentation/Splunk/6.6.1/Data/Overviewofeventprocessing)
http://docs.splunk.com/Documentation/Splunk/6.6.1/Data/Configureyourinputs
thanks somesoni2
This looked like it helped you significantly with your problem. I have converted this to an answer, If you agree it was helpful, could you mark it as Accepted? If not, ask some more!
It's hard to say where to start. Maybe at List of configuration files