splunk 手工配置

/opt/splunk/etc/users/admin/search/local/props.conf
手工添加数据输入
/opt/splunk/etc/apps/launcher/local/inputs.conf
[monitor:///home/xingwang.liuxw/data]
disabled = false
followTail = 0
sourcetype = ANAT
[udp://515]
connection_host = ip
source = tengine
sourcetype = syslog

发表评论