Monitoring Splunk

Forwarding search head logs to indexer

aoliullah
Path Finder

Hi. I have been trying to forward my search head logs to the indexer as it is a best practice. In order to do so, I tried to create an outputs.conf under search app with all the parameters. However, I wanted to try out how it can be done through the GUI, so used the "configure forwarding" option and set the IP:destport. I now receive the internal logs.

However, I am trying to find out where that GUI setting would have got written to. It should technically have created a new outputs.conf file right? Could anyone tell me where it would reside please? I have tried to use the "locate" command on my search head box to find all the outputs.conf file but couldn't find the config written to any of them.

Thanks in advance!

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi aoliullah,
usually it's in $SPLUNK_HOME/etc/system/local.
everyway, you can find it also using btool command

./splunk cmd btool outputs list --debug

Bye.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi aoliullah,
usually it's in $SPLUNK_HOME/etc/system/local.
everyway, you can find it also using btool command

./splunk cmd btool outputs list --debug

Bye.
Giuseppe

0 Karma

aoliullah
Path Finder

Thank you.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...