官术网_书友最值得收藏!

Forwarding Splunk's internal logs to the indexers

On all Splunk nodes except the indexers, we want to have all of Splunk's internal logs forwarded to the indexers instead of indexing them locally; this reduces disk space usage and it makes the internal logs for all the Splunk nodes searchable without having to log into each node individually – you can determine which node a specific log entry came from by the host field.

In the /opt/splunk/etc/system/local directory, create an outputs.conf file and add the following entries (replacing the example <ipaddress>:9997 entries with the correct IP addresses and receiving port, if different) for your indexers. We'll let this node pick up this configuration upon the next restart of Splunk after you've set up the indexers. Remember to perform this step on all of your nodes (except indexers):

[indexAndForward]
index = false

[tcpout]
defaultGroup = dev_test_indexers
forwardedindex.filter.disable = true
indexAndForward = false

[tcpout:dev_test_indexers]
server=172.31.28.223:9997,172.31.39.185:9997,172.31.13.169:9997

We're done with this node for now. We needed these components to be in place first so that we can point all the other servers to the license master for licensing, and point the indexers to this cluster master node during their setup.

主站蜘蛛池模板: 蛟河市| 马尔康县| 东丰县| 钟山县| 中西区| 吉水县| 宁明县| 常宁市| 平乐县| 会东县| 江口县| 大城县| 吴桥县| 宁河县| 霍林郭勒市| 台北市| 伊金霍洛旗| 忻州市| 宁明县| 双峰县| 肇庆市| 邢台县| 苗栗县| 苗栗县| 慈利县| 鞍山市| 长沙市| 石楼县| 昂仁县| 杭州市| 贵州省| 卓资县| 浏阳市| 石屏县| 凌云县| 盐池县| 沂南县| 罗甸县| 日土县| 区。| 兴化市|