Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to index the log data only from a single server when the log path is in shared drive

$
0
0
Hi All, I am facing the below issue: I am reading few log sources (monitor) from the 3 servers, Server1, Server2 and Server3. Along with that, I am also reading a log source (test1.txt) from a shared path (This path is shared across all 3 servers). Now, the issue is: the same log source (test1.txt) is indexed twice on Splunk against the host Server2 and Server3. Whereas, I want to index this source only once against the server Server1 and not to index for Server2 and Server3. Is there a way in config file where I can specify that test1.txt should be monitored only from Server1. How can I achieve this? Please help me. regards, Santosh

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>