Configure the universal forwarder using configuration files

Optionally edit the Universal forwarder configuration files to further modify how your machine data is streamed to your indexers. See the following steps:

  1. Find the configuration files.
  2. Edit the configuration files.
  3. Restart the universal forwarder.

Edit inputs.conf

  1. Using your operating system file management tools or a shell or command prompt, navigate to $SPLUNK_HOME/etc/system/local.
  2. Open inputs.conf for editing. You might need to create this file if it does not exist.
  3. Add your data inputs.
  4. Once you have added your inputs, save the file and close it.
  5. Restart the forwarder.
  6. On the receiving indexer, log in and load the Search and Reporting app.
  7. Run a search and confirm that you see results from the forwarder that you set up the data inputs on:

If you don't see any results, visit the Troubleshooting page for possible resolution.