Quantcast
Viewing all articles
Browse latest Browse all 47296

Splunk - Adding stanza in input.conf file

i am using Splunk enterprise trial version and trying to push the windows logs to Splunk from the customize location . I gave the path location of my file which i want to push in /etc/system/local folder inside input.conf file and restarted the splunk server but still i could not able to see the file in splunk. I have followed the below documents to add the stanza in the input.conf file https://docs.splunk.com/Documentation/Splunk/8.0.1/Data/Monitorfilesanddirectorieswithinputs.conf Can anyone please guide me in this as how to push the file ti splunk from a customize location Note- I made the changes in the input.conf file inside splunk universal forwarder directory as i dont have $splunk_home file directory

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>