<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic etc\apps\SplunkUniversalForwarder\local\inputs.conf overwriting other apps in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/etc-apps-SplunkUniversalForwarder-local-inputs-conf-overwriting/m-p/659012#M111447</link>
    <description>&lt;P&gt;Hello, everyone.&lt;/P&gt;&lt;P&gt;I just ran into an issue where a stanza within&amp;nbsp;&lt;STRONG&gt;apps\SplunkUniversalForwarder\local\inputs.conf&lt;/STRONG&gt; on a forwarder is overwriting other &lt;STRONG&gt;apps\AppName\local\inputs.conf&amp;nbsp;&lt;/STRONG&gt; from other apps in the &lt;STRONG&gt;apps&lt;/STRONG&gt; folder.&lt;/P&gt;&lt;P&gt;I would like to either disable this app, or delete the &lt;STRONG&gt;\SplunkUniversalForwarder\local&amp;nbsp;&lt;/STRONG&gt;folder or delete the stanza.&lt;/P&gt;&lt;P&gt;The problem is that this has happened on multiple hosts and I need an automated method of doing this.&lt;/P&gt;&lt;P&gt;Does anyone have an idea so that this default app that I don't even want to touch doesn't overwrite my own actually used apps?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 28 Sep 2023 20:44:10 GMT</pubDate>
    <dc:creator>Choi_Hyun</dc:creator>
    <dc:date>2023-09-28T20:44:10Z</dc:date>
    <item>
      <title>etc\apps\SplunkUniversalForwarder\local\inputs.conf overwriting other apps</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/etc-apps-SplunkUniversalForwarder-local-inputs-conf-overwriting/m-p/659012#M111447</link>
      <description>&lt;P&gt;Hello, everyone.&lt;/P&gt;&lt;P&gt;I just ran into an issue where a stanza within&amp;nbsp;&lt;STRONG&gt;apps\SplunkUniversalForwarder\local\inputs.conf&lt;/STRONG&gt; on a forwarder is overwriting other &lt;STRONG&gt;apps\AppName\local\inputs.conf&amp;nbsp;&lt;/STRONG&gt; from other apps in the &lt;STRONG&gt;apps&lt;/STRONG&gt; folder.&lt;/P&gt;&lt;P&gt;I would like to either disable this app, or delete the &lt;STRONG&gt;\SplunkUniversalForwarder\local&amp;nbsp;&lt;/STRONG&gt;folder or delete the stanza.&lt;/P&gt;&lt;P&gt;The problem is that this has happened on multiple hosts and I need an automated method of doing this.&lt;/P&gt;&lt;P&gt;Does anyone have an idea so that this default app that I don't even want to touch doesn't overwrite my own actually used apps?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 20:44:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/etc-apps-SplunkUniversalForwarder-local-inputs-conf-overwriting/m-p/659012#M111447</guid>
      <dc:creator>Choi_Hyun</dc:creator>
      <dc:date>2023-09-28T20:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: etc\apps\SplunkUniversalForwarder\local\inputs.conf overwriting other apps</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/etc-apps-SplunkUniversalForwarder-local-inputs-conf-overwriting/m-p/659041#M111449</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/258431"&gt;@Choi_Hyun&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the UniversalForwarder App is an internal Splunk App and usually it isn't used to add configurations, how do you have an inputs.conf in this App?&lt;/P&gt;&lt;P&gt;Anyway, I'm not sure that it's possible to manage this App using a Deployment Server, but if you have the inputs.conf file in local you could try to deploy this App with an inputs.conf with this stanza disabled.&lt;/P&gt;&lt;P&gt;Otherwise, the only solution is a remote script shell that remove this file (not the App!) and restarts Splunk.&lt;/P&gt;&lt;P&gt;I'm very confident about this last solution.&lt;/P&gt;&lt;P&gt;If all the above solutions don't work, open a case to Splunk Support.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 06:49:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/etc-apps-SplunkUniversalForwarder-local-inputs-conf-overwriting/m-p/659041#M111449</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-29T06:49:54Z</dc:date>
    </item>
    <item>
      <title>Re: etc\apps\SplunkUniversalForwarder\local\inputs.conf overwriting other apps</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/etc-apps-SplunkUniversalForwarder-local-inputs-conf-overwriting/m-p/659315#M111525</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Giuseppe,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thank you for your response.&lt;/P&gt;&lt;P&gt;I also have no idea why an input.conf file was created or how it was created.&lt;/P&gt;&lt;P&gt;I will test to see if my deployment server can push out an empty input.conf file to that folder, otherwise I might just have to use PowerShell to just delete and replace that file on our hosts.&lt;/P&gt;&lt;P&gt;To make it clear, this behavior is unusual right?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2023 16:03:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/etc-apps-SplunkUniversalForwarder-local-inputs-conf-overwriting/m-p/659315#M111525</guid>
      <dc:creator>Choi_Hyun</dc:creator>
      <dc:date>2023-10-02T16:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: etc\apps\SplunkUniversalForwarder\local\inputs.conf overwriting other apps</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/etc-apps-SplunkUniversalForwarder-local-inputs-conf-overwriting/m-p/659317#M111526</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/258431"&gt;@Choi_Hyun&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as I said, for my knowledge, that app shouldn't be used for inputs.&lt;/P&gt;&lt;P&gt;also because it isn't possible to manage it by Deployment Server.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2023 16:41:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/etc-apps-SplunkUniversalForwarder-local-inputs-conf-overwriting/m-p/659317#M111526</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-10-02T16:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: etc\apps\SplunkUniversalForwarder\local\inputs.conf overwriting other apps</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/etc-apps-SplunkUniversalForwarder-local-inputs-conf-overwriting/m-p/659344#M111531</link>
      <description>&lt;P&gt;Ok. That's interesting because the SplunkUniversalForwarder app is an app which indeed as &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt; pointed out comes with your UF installation but it typically does not contain the local directory. As far as I remember the configurations you make with CLI splunk commands (like splunk add monitor) land in etc/system/local directory so they should not be there either.&lt;/P&gt;&lt;P&gt;While technically you can make changes to the default apps you shouldn't do so because in case of upgrade you'll overwrite the changes in apps that come with the installation package with your own versions again which might be undesirable. So you should not touch the default apps.&lt;/P&gt;&lt;P&gt;So I'd try to see where did those settings come from - either someone configured them manually (which is the "least bad" case here because on upgrade the "default" directory should get overwritten but "local" should should stay untouched) or your DS is serving this app (in which case you might want to check where it is being pushed to).&lt;/P&gt;&lt;P&gt;Anyway, if it's been done manually, you can always just do your favourite configuration automation software (ansible?) and just remove the file from your UFs. Or you can just deploy an app with a higher precedence which will override the settings from the problematic config. See &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.1/Admin/Wheretofindtheconfigurationfiles" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.1/Admin/Wheretofindtheconfigurationfiles&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2023 21:33:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/etc-apps-SplunkUniversalForwarder-local-inputs-conf-overwriting/m-p/659344#M111531</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-10-02T21:33:04Z</dc:date>
    </item>
    <item>
      <title>Re: etc\apps\SplunkUniversalForwarder\local\inputs.conf overwriting other apps</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/etc-apps-SplunkUniversalForwarder-local-inputs-conf-overwriting/m-p/659585#M111557</link>
      <description>&lt;P&gt;i&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/258431"&gt;@Choi_Hyun&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2023 06:53:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/etc-apps-SplunkUniversalForwarder-local-inputs-conf-overwriting/m-p/659585#M111557</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-10-04T06:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: etc\apps\SplunkUniversalForwarder\local\inputs.conf overwriting other apps</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/etc-apps-SplunkUniversalForwarder-local-inputs-conf-overwriting/m-p/659649#M111573</link>
      <description>&lt;P&gt;My DS doesn't have an explicit stanza to push SplunkUniversalForwarder app. I know that the file the other app the DS pushed did not exist on all hosts the app got pushed to.&lt;BR /&gt;&lt;BR /&gt;Is it possible Splunk automatically decided to create a stanza on one of its input.conf file because it kept finding out that the file did not exist? We now have this file being logged on all hosts so now I have to manually change the input.conf file.&lt;BR /&gt;&lt;BR /&gt;I also thought that my other non-default apps took precedence before the default SplunkUniversalForwarder app, but when I ran btool, it told me the file I was looking for was obtaining its configuration from \etc\apps\SplunkUniversalForwarder\local\input.conf instead of anywhere else.&lt;BR /&gt;&lt;BR /&gt;What's truely strange is that this behavior is only happening on some hosts and not others.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2023 13:20:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/etc-apps-SplunkUniversalForwarder-local-inputs-conf-overwriting/m-p/659649#M111573</guid>
      <dc:creator>Choi_Hyun</dc:creator>
      <dc:date>2023-10-04T13:20:02Z</dc:date>
    </item>
  </channel>
</rss>

