Can someone please provide an example of what the outputs.conf file would look like on a universal forwarder in an index clustered environment?
For example: 1 sh, 2 indexers, 1 clustering Master, 4 nodes with universal forward ready to send data once the setup is complete.
Rep factor 2, search factor 2
**1) idx1:9997
2) idx2:9997
3) clustermaster:8089**
I've been searching Splunk documentation, but it only provides examples for load balancing forwarders.
Can someone please provide an example of what the outputs.conf file should look like?
↧