I am forwarding the data from forwarder to indexer. I am able to see the default log files that forwarder forwards to indexer, but not able to see the monitored file in indexer and no error is being logged in forwarder and indexers splunkd.log and metrics.log.
My inputs.conf Configuration:
inputs.conf
[monitor:///var/log/test]
disabled = false
sourcetype = test
index=tutorial
Outputs.conf
[tcpout]
defaultGroup = default-autolb-group
[tcpout:default-autolb-group]
server = 10.87.36.181:9997
[tcpout-server://10.87.36.181:9997]
Tried to run Splunk list monitor in forwarder:
Monitored directories:
/var/log/test
/var/log/test/service.log
/var/log/test/testSplunk
Please suggest on the same.
↧