<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic input.conf first timer in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/input-conf-first-timer/m-p/66705#M13403</link>
    <description>&lt;P&gt;All, &lt;/P&gt;

&lt;P&gt;I just finished day 1 of the administration of Splunk class. Gotta admit to being lost.So I fired up a lab, 3 VMs. splunk01, host01, deploy01 and DC01 (for DNS). &lt;/P&gt;

&lt;P&gt;Installed Splunk on Splunk01 and it worked. Enabled the listening on 9997. Installed the forwarders on host01. I can see the host check in when I do a search with &lt;CODE&gt;index=_internal *splunkforwarder*&lt;/CODE&gt; as we did in the class. &lt;/P&gt;

&lt;P&gt;But I made my own little "app". I created a folder under /opt/splunkforwarder/etc/myappname and folder under there called /local&lt;/P&gt;

&lt;P&gt;My inputs.conf which I placed in /local  reads as follows&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///var/log/messages]
disabled = 0
index=main
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I restarted the forwarder, waited. Nothing ever came through. Any ideas to what I should be checking now? &lt;/P&gt;</description>
    <pubDate>Tue, 18 Dec 2012 05:18:35 GMT</pubDate>
    <dc:creator>daniel333</dc:creator>
    <dc:date>2012-12-18T05:18:35Z</dc:date>
    <item>
      <title>input.conf first timer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/input-conf-first-timer/m-p/66705#M13403</link>
      <description>&lt;P&gt;All, &lt;/P&gt;

&lt;P&gt;I just finished day 1 of the administration of Splunk class. Gotta admit to being lost.So I fired up a lab, 3 VMs. splunk01, host01, deploy01 and DC01 (for DNS). &lt;/P&gt;

&lt;P&gt;Installed Splunk on Splunk01 and it worked. Enabled the listening on 9997. Installed the forwarders on host01. I can see the host check in when I do a search with &lt;CODE&gt;index=_internal *splunkforwarder*&lt;/CODE&gt; as we did in the class. &lt;/P&gt;

&lt;P&gt;But I made my own little "app". I created a folder under /opt/splunkforwarder/etc/myappname and folder under there called /local&lt;/P&gt;

&lt;P&gt;My inputs.conf which I placed in /local  reads as follows&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///var/log/messages]
disabled = 0
index=main
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I restarted the forwarder, waited. Nothing ever came through. Any ideas to what I should be checking now? &lt;/P&gt;</description>
      <pubDate>Tue, 18 Dec 2012 05:18:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/input-conf-first-timer/m-p/66705#M13403</guid>
      <dc:creator>daniel333</dc:creator>
      <dc:date>2012-12-18T05:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: input.conf first timer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/input-conf-first-timer/m-p/66706#M13404</link>
      <description>&lt;P&gt;You have ommitted the apps directory from the path :&lt;/P&gt;

&lt;P&gt;/opt/splunkforwarder/etc/&lt;STRONG&gt;apps&lt;/STRONG&gt;/myappname/local/inputs.conf&lt;/P&gt;</description>
      <pubDate>Tue, 18 Dec 2012 06:47:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/input-conf-first-timer/m-p/66706#M13404</guid>
      <dc:creator>Damien_Dallimor</dc:creator>
      <dc:date>2012-12-18T06:47:44Z</dc:date>
    </item>
  </channel>
</rss>

