Splunk forwarder (Windows and Linux)

Configuration of log shipper 'splunk forwarder'

This section explains how you can configure 'Splunk' like a log shipper.

In order for the Splunk component to send the log details to the event gateway, users have to configure two elements.

  1. Event Gateway Endpoint

  2. Splunk configuration on Linux/Windows configuration

Step 1:

An example Event Gateway Endpoint configuration is captured in the below configuration snippet.

Gateway Endpoint:
endpoints:
- name: winodows_events
  enabled: true
  type: tcp_json
  port: 9997
  attrs:
    site_code: dc1
    archive_name: splunk_events
  stream: windows-splunk-stream 

Step 2:

Update the input and output.conf file from the below path:

Input conf file:

outputs.conf file:

Step 3:

Restart splunk service

Last updated