<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: uf install didn't create inputs.conf in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/uf-install-didn-t-create-inputs-conf/m-p/31535#M5545</link>
    <description>&lt;P&gt;What are "forwarding events" , is it a WinEventLog channel ?&lt;/P&gt;

&lt;P&gt;inputs.conf can be in many locations.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;$SPLUNK_HOME/etc/system/local&lt;/LI&gt;
&lt;LI&gt;$SPLUNK_HOME/etc/apps/search/local&lt;/LI&gt;
&lt;LI&gt;$SPLUNK_HOME/etc/apps/MSI-created/local&lt;/LI&gt;
&lt;LI&gt;$SPLUNK_HOME/etc/apps/&lt;MYAPP&gt;/local&lt;/MYAPP&gt;&lt;/LI&gt;
&lt;LI&gt;etc...&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Mon, 13 May 2013 15:25:42 GMT</pubDate>
    <dc:creator>yannK</dc:creator>
    <dc:date>2013-05-13T15:25:42Z</dc:date>
    <item>
      <title>uf install didn't create inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/uf-install-didn-t-create-inputs-conf/m-p/31534#M5544</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I installed a UF on a windows server, and asked it to monitor Forwarding Events, but I don't see anything create in inputs.conf. Is it stored anywhere?&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2013 15:15:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/uf-install-didn-t-create-inputs-conf/m-p/31534#M5544</guid>
      <dc:creator>a212830</dc:creator>
      <dc:date>2013-05-13T15:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: uf install didn't create inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/uf-install-didn-t-create-inputs-conf/m-p/31535#M5545</link>
      <description>&lt;P&gt;What are "forwarding events" , is it a WinEventLog channel ?&lt;/P&gt;

&lt;P&gt;inputs.conf can be in many locations.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;$SPLUNK_HOME/etc/system/local&lt;/LI&gt;
&lt;LI&gt;$SPLUNK_HOME/etc/apps/search/local&lt;/LI&gt;
&lt;LI&gt;$SPLUNK_HOME/etc/apps/MSI-created/local&lt;/LI&gt;
&lt;LI&gt;$SPLUNK_HOME/etc/apps/&lt;MYAPP&gt;/local&lt;/MYAPP&gt;&lt;/LI&gt;
&lt;LI&gt;etc...&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 13 May 2013 15:25:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/uf-install-didn-t-create-inputs-conf/m-p/31535#M5545</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2013-05-13T15:25:42Z</dc:date>
    </item>
    <item>
      <title>Re: uf install didn't create inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/uf-install-didn-t-create-inputs-conf/m-p/31536#M5546</link>
      <description>&lt;P&gt;When you install the forwarder, the gui asks if you want to monitor certain files, and that's one of them.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2013 15:27:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/uf-install-didn-t-create-inputs-conf/m-p/31536#M5546</guid>
      <dc:creator>a212830</dc:creator>
      <dc:date>2013-05-13T15:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: uf install didn't create inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/uf-install-didn-t-create-inputs-conf/m-p/31537#M5547</link>
      <description>&lt;P&gt;Just found it - MSI.... Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2013 15:28:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/uf-install-didn-t-create-inputs-conf/m-p/31537#M5547</guid>
      <dc:creator>a212830</dc:creator>
      <dc:date>2013-05-13T15:28:26Z</dc:date>
    </item>
    <item>
      <title>Re: uf install didn't create inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/uf-install-didn-t-create-inputs-conf/m-p/546798#M91046</link>
      <description>&lt;P&gt;I have a similar issue, I have created an app&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;distributed it to my windows server2016 and only the app.conf appears on the server after deployment&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;steps I did:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;created an app with inputs.conf file&amp;nbsp; in my&amp;nbsp;&lt;SPAN&gt;deployment server (/opt/splunk/etc/deployment-apps/my_app/local/inputs.conf)&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;created a relevant server class&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Attached my app to the server class&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Made sure that my server is in the include list of the sever class.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;splunk apply shcluster-bundle&amp;nbsp; --target &lt;A href="https://SH:8089" target="_blank" rel="noopener"&gt;https://SH:8089&lt;/A&gt;&amp;nbsp;--answer-yes.&lt;/LI&gt;&lt;LI&gt;RDP to server - the directory been created but only app.conf&lt;/LI&gt;&lt;LI&gt;I have tried to troubleshoot by deleting the local copy of the app on the server and&amp;nbsp;&lt;SPAN&gt;disabled any security policy on that server and rerun step 5 - with the same result.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;please advise &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 06:24:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/uf-install-didn-t-create-inputs-conf/m-p/546798#M91046</guid>
      <dc:creator>wildbird</dc:creator>
      <dc:date>2021-04-06T06:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: uf install didn't create inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/uf-install-didn-t-create-inputs-conf/m-p/546801#M91048</link>
      <description>&lt;P&gt;Hİ&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229709"&gt;@wildbird&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;splunk apply shcluster-bundle&amp;nbsp; --target &lt;/SPAN&gt;&lt;A href="https://SH:8089" target="_blank" rel="noopener nofollow noreferrer"&gt;https://SH:8089&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;--answer-yes&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ths command is not for deployment server, you should use below instead;&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk reload deploy-server&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 06:39:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/uf-install-didn-t-create-inputs-conf/m-p/546801#M91048</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-04-06T06:39:59Z</dc:date>
    </item>
    <item>
      <title>Re: uf install didn't create inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/uf-install-didn-t-create-inputs-conf/m-p/546802#M91049</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it's solved my issue!&lt;/P&gt;&lt;P&gt;Thank you very much!&lt;/P&gt;&lt;P&gt;can you please help me understand what I did wrong?&lt;/P&gt;&lt;P&gt;when do I use:&amp;nbsp;&lt;SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;Splunk apply shcluster-bundle&lt;/STRONG&gt;&lt;/EM&gt; and when to use&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;splunk reload deploy-server&lt;/STRONG&gt;&lt;/EM&gt;?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 06:47:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/uf-install-didn-t-create-inputs-conf/m-p/546802#M91049</guid>
      <dc:creator>wildbird</dc:creator>
      <dc:date>2021-04-06T06:47:56Z</dc:date>
    </item>
    <item>
      <title>Re: uf install didn't create inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/uf-install-didn-t-create-inputs-conf/m-p/546820#M91053</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229709"&gt;@wildbird&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Great &amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"splunk apply shcluster-bundle" command is for &lt;STRONG&gt;Deployer&lt;/STRONG&gt; to push the apps from $SPLUNK_HOME/etc/shcluster/apps to Search Head Cluster members.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.3/DistSearch/PropagateSHCconfigurationchanges" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.3/DistSearch/PropagateSHCconfigurationchanges&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"splunk reload deploy-server" command is for &lt;STRONG&gt;Deployment Server&lt;/STRONG&gt; to update Deployment server apps/serverclass bundles hashes on&amp;nbsp;$SPLUNK_HOME/etc/deployment-apps folder. Deployment clients like Universal Forwarders will get the new apps on their next requests.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.3/Updating/Updateconfigurations" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.3/Updating/Updateconfigurations&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sometimes it is confusing since both commands is related to Deploy&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 08:52:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/uf-install-didn-t-create-inputs-conf/m-p/546820#M91053</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-04-06T08:52:00Z</dc:date>
    </item>
  </channel>
</rss>

