<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configure input.conf for universal forwader in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Configure-input-conf-for-universal-forwader/m-p/78769#M16130</link>
    <description>&lt;P&gt;Note that the file should be called &lt;CODE&gt;inputs.conf&lt;/CODE&gt;, not &lt;CODE&gt;input.conf&lt;/CODE&gt;.&lt;/P&gt;</description>
    <pubDate>Wed, 20 Jun 2012 07:30:32 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2012-06-20T07:30:32Z</dc:date>
    <item>
      <title>Configure input.conf for universal forwader</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-input-conf-for-universal-forwader/m-p/78767#M16128</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;I've installed splunk indexer on a linux server and universal splunk forwarder on a windows machine,while installing the universal forwader I enabled few logs for forwarding such as&lt;/P&gt;

&lt;P&gt;1 WinEventLog:Application &lt;BR /&gt;
2 WinEventLog:System &lt;BR /&gt;
3 Perfmon:CPU Load &lt;BR /&gt;
4 Perfmon:Available Memory&lt;BR /&gt;
5 Perfmon:Free Disk Space &lt;/P&gt;

&lt;P&gt;And this is working as I see this the above splunk indexer ,NOw I want to remove this one and point my application logs in the universal forwader so that I can view the application logs in indexer&lt;BR /&gt;
How to do this? I tried to do this by editing the input.conf file at /splunkhome/etc/system/local - but no luck - also I need to give new inputs such as my application logs - where do I add this in universal forwader?I'm kind of confused between inputs.conf and output.conf- Can any one please help&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2012 18:22:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-input-conf-for-universal-forwader/m-p/78767#M16128</guid>
      <dc:creator>splunker_123</dc:creator>
      <dc:date>2012-06-19T18:22:22Z</dc:date>
    </item>
    <item>
      <title>Re: Configure input.conf for universal forwader</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-input-conf-for-universal-forwader/m-p/78768#M16129</link>
      <description>&lt;P&gt;please look in &lt;CODE&gt;$SPLUNK_HOME\etc\apps\&amp;lt;nameoftheapp&amp;gt;\local\input.conf&lt;/CODE&gt;&lt;BR /&gt;
the app folder name may be MSIinstaller*, but i am not 100% sure.&lt;BR /&gt;
You should find the ones built by the installer wizard, and use them a model to add new ones.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2012 05:56:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-input-conf-for-universal-forwader/m-p/78768#M16129</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2012-06-20T05:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: Configure input.conf for universal forwader</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-input-conf-for-universal-forwader/m-p/78769#M16130</link>
      <description>&lt;P&gt;Note that the file should be called &lt;CODE&gt;inputs.conf&lt;/CODE&gt;, not &lt;CODE&gt;input.conf&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2012 07:30:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-input-conf-for-universal-forwader/m-p/78769#M16130</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-06-20T07:30:32Z</dc:date>
    </item>
    <item>
      <title>Re: Configure input.conf for universal forwader</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-input-conf-for-universal-forwader/m-p/78770#M16131</link>
      <description>&lt;P&gt;Are you saying that I have to edit the inputs.conf under $SPLUNK_HOME\etc\apps\MSlinstaller\input.conf and not under system\local\inputs.conf?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2012 08:57:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-input-conf-for-universal-forwader/m-p/78770#M16131</guid>
      <dc:creator>splunker_123</dc:creator>
      <dc:date>2012-06-20T08:57:47Z</dc:date>
    </item>
    <item>
      <title>Re: Configure input.conf for universal forwader</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-input-conf-for-universal-forwader/m-p/78771#M16132</link>
      <description>&lt;P&gt;You can edit either, at the end splunk merges all the configuration from every enabled app and system.&lt;/P&gt;

&lt;P&gt;What I was saying is that the inputs created by the windows installer are usually in an app named "MSIsomething". If you want to use them as model.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2012 14:57:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-input-conf-for-universal-forwader/m-p/78771#M16132</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2012-06-20T14:57:57Z</dc:date>
    </item>
  </channel>
</rss>

