<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: edit inputs.conf in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/edit-inputs-conf/m-p/93361#M19418</link>
    <description>&lt;P&gt;You need to check the file permissions in Windows to determine why you are getting an access denied when trying to edit that file.&lt;/P&gt;

&lt;P&gt;That said, you shouldn't be editing the inputs.conf file in "default". Best practice for all your own modifications is to create an inputs.conf in "local" instead (so full path would be &lt;CODE&gt;"C:\Program Files\Splunk\etc\apps\SplunkLightForwarder\local\inputs.conf"&lt;/CODE&gt;). Any settings in this file will override the ones in "default".&lt;/P&gt;</description>
    <pubDate>Tue, 18 Oct 2011 09:00:16 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2011-10-18T09:00:16Z</dc:date>
    <item>
      <title>edit inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/edit-inputs-conf/m-p/93359#M19416</link>
      <description>&lt;P&gt;I have a issue with picking up the keyword from a tail of a text file. Reading through the documention found that there is a suggestion to add 'followTail = 1' to the inputs.conf file.&lt;BR /&gt;
Now ( i hope i am right) the input.conf that i need to edit is:&lt;BR /&gt;
C:\Program Files\Splunk\etc\apps\SplunkLightForwarder\default&lt;/P&gt;

&lt;P&gt;unfortunately, this file cannot be edited or saved, as system complains that 'access is denied'.&lt;BR /&gt;
Then i stopped the splunkd and splunkweb, services, and put them as manual rather than automatic, and restarted the machine. Verified that the services mentioned were not running, but still there seems to be a lock on the file.&lt;BR /&gt;
I am editing the correct inputs.conf file?&lt;BR /&gt;
How can i successfully edit the file and add the changes?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2011 08:22:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/edit-inputs-conf/m-p/93359#M19416</guid>
      <dc:creator>rashidmirza</dc:creator>
      <dc:date>2011-10-18T08:22:24Z</dc:date>
    </item>
    <item>
      <title>Re: edit inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/edit-inputs-conf/m-p/93360#M19417</link>
      <description>&lt;P&gt;You should create an inputs.conf file in the "local" directory of the target app(SplunkLightForwarder) and make your changes there.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2011 08:56:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/edit-inputs-conf/m-p/93360#M19417</guid>
      <dc:creator>Damien_Dallimor</dc:creator>
      <dc:date>2011-10-18T08:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: edit inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/edit-inputs-conf/m-p/93361#M19418</link>
      <description>&lt;P&gt;You need to check the file permissions in Windows to determine why you are getting an access denied when trying to edit that file.&lt;/P&gt;

&lt;P&gt;That said, you shouldn't be editing the inputs.conf file in "default". Best practice for all your own modifications is to create an inputs.conf in "local" instead (so full path would be &lt;CODE&gt;"C:\Program Files\Splunk\etc\apps\SplunkLightForwarder\local\inputs.conf"&lt;/CODE&gt;). Any settings in this file will override the ones in "default".&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2011 09:00:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/edit-inputs-conf/m-p/93361#M19418</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2011-10-18T09:00:16Z</dc:date>
    </item>
    <item>
      <title>Re: edit inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/edit-inputs-conf/m-p/93362#M19419</link>
      <description>&lt;P&gt;well, i have added the inputs.conf file to the folder that was suggested.&lt;BR /&gt;
I am now struggling with what condition to put for the alerts. Basically the following are at disposal:&lt;BR /&gt;
1)always&lt;BR /&gt;
2)if number of events&lt;BR /&gt;
3)if number of hosts&lt;BR /&gt;
4)if number of sources&lt;BR /&gt;
5)if custom condition is met&lt;/P&gt;

&lt;P&gt;need to know which one to define, so that the alert is sent out the moment the keyword is there in the new text that was written to in the dynamic text file.&lt;/P&gt;

&lt;P&gt;Also i have set the start time as 'rt-60s' and finish time as 'rt'.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2011 11:31:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/edit-inputs-conf/m-p/93362#M19419</guid>
      <dc:creator>rashidmirza</dc:creator>
      <dc:date>2011-10-18T11:31:54Z</dc:date>
    </item>
    <item>
      <title>Re: edit inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/edit-inputs-conf/m-p/93363#M19420</link>
      <description>&lt;P&gt;That is another question, and as such you should post it separately.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2011 11:42:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/edit-inputs-conf/m-p/93363#M19420</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2011-10-18T11:42:10Z</dc:date>
    </item>
  </channel>
</rss>

