Article 4Q0RP Splunk

Splunk

by
1s440
from LinuxQuestions.org on (#4Q0RP)
Hi all,

I am trying to setup splunk to monitor all the remote hosts on a Splunk server. Without any issues, i have set up the Splunk server. I have installed the Universal forwader on Remote host and provides inputs.conf and outputs.conf as below. But some how these logs are not getting routed to Splunk server. I am stuck here though i change some configuration according to the Splunk documentation, i have not got the output. can anyone suggest me.

Code:inputs.conf
[default]
[monitor:///var/log/messages]
disabled = 0
source type = messages_log
index = system_logCode:outputs.conf
[tcpout:default-autolb-group]
disabled = false
server = 192.189.11.34:9997latest?d=yIl2AUoC8zA latest?i=zW2Ca_xbxsY:WIuYyatr0qo:F7zBnMy latest?i=zW2Ca_xbxsY:WIuYyatr0qo:V_sGLiP latest?d=qj6IDK7rITs latest?i=zW2Ca_xbxsY:WIuYyatr0qo:gIN9vFwzW2Ca_xbxsY
External Content
Source RSS or Atom Feed
Feed Location https://feeds.feedburner.com/linuxquestions/latest
Feed Title LinuxQuestions.org
Feed Link https://www.linuxquestions.org/questions/
Reply 0 comments