My inputs.conf at /opt/splunkforwarder/etc/system/local/inputs.conf looks like
[monitor:///var/log/journal/dcf370a7752c4b14b6f7be387fabdf5f/system.journal]
_TCP_ROUTING = IHF-ext_encrypted
ignoreOlderThan = 7d
index = os
disabled = 0
sourcetype = syslog
My inputs.conf at /opt/splunkforwarder/etc/system/local/inputs.conf looks like [monitor:///var/log/journal/dcf370a7752c4b14b6f7be387fabdf5f/system.journal] _TCP_ROUTING = IHF-ext_encrypted ignoreOlderThan = 7d index = os disabled = 0 sourcetype = syslog
But I can not see logs in splunk