November 2018
Beginner
298 pages
7h 51m
English
To get started and serve as an example, let's create a couple of apps on the deployment server to distribute the outputs.conf file to all of the forwarders, and then set up an inputs.conf for an example web server.
On the deployment server, create an outputs.conf file in a new folder called forwarder_outputs and a /local folder under that, in $SPLUNK_HOME/etc /deployment-apps. You'll note this is the same content we configured in the section on installing a universal forwarder – we're just going to manage and distribute this file from the deployment server instead of having to do it manually on each forwarder. This makes it possible to update this file easily if you add more indexers to your cluster down ...
Read now
Unlock full access