<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Deployment Server and Universal Forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Deployment-Server-and-Universal-Forwarder-Which-file-is-being/m-p/612531#M105986</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;it's just like&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;said. When the app name is same (installed into same path) then DS win. You could also check it with btool on UF side. Just&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk btool inputs list monitor:///var/log --debug&lt;/LI-CODE&gt;&lt;P&gt;and then look the output which shows all monitored files under /var/log&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Fri, 09 Sep 2022 08:45:58 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2022-09-09T08:45:58Z</dc:date>
    <item>
      <title>Deployment Server and Universal Forwarder- Which file is being monitored?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Deployment-Server-and-Universal-Forwarder-Which-file-is-being/m-p/612517#M105984</link>
      <description>&lt;P&gt;I saw a question on the internet while searching for answers for a separate question and a few comments below regarding the correct answer for that. Now, I am confused as to what&amp;nbsp; should have been the correct answer. This was the question.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;This file has been manually created on a universal forwarder:&lt;/P&gt;
&lt;P&gt;/opt/splunkforwarder/etc/apps/my_TA/local/inputs.conf&lt;BR /&gt;[monitor:///var/log/messages]&lt;BR /&gt;sourcetype=syslog&lt;BR /&gt;index=syslog&lt;/P&gt;
&lt;P&gt;A new Splunk admin comes in and connects the universal forwarders to a deployment server and deploys the same app with a new inputs.conf file:&lt;/P&gt;
&lt;P&gt;/opt/splunk/etc/deployment-apps/my_TA/local/inputs.conf&lt;BR /&gt;[monitor:///var/log/maillog]&lt;BR /&gt;sourcetype=maillog&lt;BR /&gt;index=syslog&lt;/P&gt;
&lt;P&gt;Which file is now monitored?&lt;BR /&gt;&lt;SPAN&gt;/var/log/maillog or both&amp;nbsp;/var/log/maillog and&amp;nbsp;/var/log/messages&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 07:57:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Deployment-Server-and-Universal-Forwarder-Which-file-is-being/m-p/612517#M105984</guid>
      <dc:creator>phularah</dc:creator>
      <dc:date>2022-09-09T07:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server and Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Deployment-Server-and-Universal-Forwarder-Which-file-is-being/m-p/612518#M105985</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/94646"&gt;@phularah&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;when you connect a client to a Deployment Server, all the local apps will be removed and the apps for the ServerClass containing that client will be deployed.&lt;/P&gt;&lt;P&gt;So if the local inputs.conf is in an app (as it seems from your information), it will be removed.&lt;/P&gt;&lt;P&gt;If you want to monitor both the folders, you have to insert the local stanza in the deployed app.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 07:05:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Deployment-Server-and-Universal-Forwarder-Which-file-is-being/m-p/612518#M105985</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-09T07:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server and Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Deployment-Server-and-Universal-Forwarder-Which-file-is-being/m-p/612531#M105986</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;it's just like&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;said. When the app name is same (installed into same path) then DS win. You could also check it with btool on UF side. Just&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk btool inputs list monitor:///var/log --debug&lt;/LI-CODE&gt;&lt;P&gt;and then look the output which shows all monitored files under /var/log&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 08:45:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Deployment-Server-and-Universal-Forwarder-Which-file-is-being/m-p/612531#M105986</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-09-09T08:45:58Z</dc:date>
    </item>
  </channel>
</rss>

