<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Where to make configuration changes in inputs.conf and outputs.conf on Linux? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Where-to-make-configuration-changes-in-inputs-conf-and-outputs/m-p/373512#M67692</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;I have installed Splunk setup on one of my VM. On another VM I installed the Splunk universal forwarder to send the logs to Splunk Server. &lt;/P&gt;

&lt;P&gt;I copied to make changes for inputs.conf and outputs.conf files to local folder to make changes because on default folder we shouldn't do changes.&lt;/P&gt;

&lt;P&gt;So, they were so many attributes  to make changes in both files. I am in confusion state.&lt;/P&gt;

&lt;P&gt;Please tell me the basic values like where to insert host , source, sourcetype names, monitor file names, index name, etc in inputs.conf and where to give Splunk Server or Indexer IP, port number in outputs.conf.&lt;/P&gt;

&lt;P&gt;Because i am setting up  my test environment so that I wont do mistakes in my production environment .&lt;/P&gt;

&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;
Ravi&lt;/P&gt;</description>
    <pubDate>Wed, 28 Jun 2017 16:06:57 GMT</pubDate>
    <dc:creator>ravisplunksap</dc:creator>
    <dc:date>2017-06-28T16:06:57Z</dc:date>
    <item>
      <title>Where to make configuration changes in inputs.conf and outputs.conf on Linux?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-to-make-configuration-changes-in-inputs-conf-and-outputs/m-p/373512#M67692</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;I have installed Splunk setup on one of my VM. On another VM I installed the Splunk universal forwarder to send the logs to Splunk Server. &lt;/P&gt;

&lt;P&gt;I copied to make changes for inputs.conf and outputs.conf files to local folder to make changes because on default folder we shouldn't do changes.&lt;/P&gt;

&lt;P&gt;So, they were so many attributes  to make changes in both files. I am in confusion state.&lt;/P&gt;

&lt;P&gt;Please tell me the basic values like where to insert host , source, sourcetype names, monitor file names, index name, etc in inputs.conf and where to give Splunk Server or Indexer IP, port number in outputs.conf.&lt;/P&gt;

&lt;P&gt;Because i am setting up  my test environment so that I wont do mistakes in my production environment .&lt;/P&gt;

&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;
Ravi&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 16:06:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-to-make-configuration-changes-in-inputs-conf-and-outputs/m-p/373512#M67692</guid>
      <dc:creator>ravisplunksap</dc:creator>
      <dc:date>2017-06-28T16:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: Where to make configuration changes in inputs.conf and outputs.conf on Linux?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-to-make-configuration-changes-in-inputs-conf-and-outputs/m-p/373513#M67693</link>
      <description>&lt;P&gt;It's hard to say where to start. Maybe at &lt;A href="https://docs.splunk.com/Documentation/Splunk/6.6.1/Admin/Listofconfigurationfiles"&gt;List of configuration files&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 16:55:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-to-make-configuration-changes-in-inputs-conf-and-outputs/m-p/373513#M67693</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-06-28T16:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: Where to make configuration changes in inputs.conf and outputs.conf on Linux?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-to-make-configuration-changes-in-inputs-conf-and-outputs/m-p/373514#M67694</link>
      <description>&lt;P&gt;Steps should be like this&lt;/P&gt;

&lt;P&gt;Configure Receiver (if not already done) &lt;A href="https://docs.splunk.com/Documentation/Forwarder/6.6.1/Forwarder/Enableareceiver"&gt;https://docs.splunk.com/Documentation/Forwarder/6.6.1/Forwarder/Enableareceiver&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Configure Forwarding&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Forwarder/6.5.2/Forwarder/Configureforwardingwithoutputs.conf"&gt;http://docs.splunk.com/Documentation/Forwarder/6.5.2/Forwarder/Configureforwardingwithoutputs.conf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Configure Data inputs. THis step generally have a pre-requisite of configuring event processing (&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.1/Data/Overviewofeventprocessing"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.1/Data/Overviewofeventprocessing&lt;/A&gt;)&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.1/Data/Configureyourinputs"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.1/Data/Configureyourinputs&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 17:03:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-to-make-configuration-changes-in-inputs-conf-and-outputs/m-p/373514#M67694</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-06-28T17:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: Where to make configuration changes in inputs.conf and outputs.conf on Linux?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-to-make-configuration-changes-in-inputs-conf-and-outputs/m-p/373515#M67695</link>
      <description>&lt;P&gt;thanks somesoni2&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2017 06:32:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-to-make-configuration-changes-in-inputs-conf-and-outputs/m-p/373515#M67695</guid>
      <dc:creator>ravisplunksap</dc:creator>
      <dc:date>2017-06-30T06:32:44Z</dc:date>
    </item>
    <item>
      <title>Re: Where to make configuration changes in inputs.conf and outputs.conf on Linux?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-to-make-configuration-changes-in-inputs-conf-and-outputs/m-p/373516#M67696</link>
      <description>&lt;P&gt;This looked like it helped you significantly with your problem.  I have converted this to an answer, If you agree it was helpful, could you mark it as Accepted?  If not, ask some more!&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2017 14:09:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-to-make-configuration-changes-in-inputs-conf-and-outputs/m-p/373516#M67696</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2017-06-30T14:09:24Z</dc:date>
    </item>
  </channel>
</rss>

