<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to add a data input in Server GUI that modifies the inputs.conf file in the Universal Forwarders? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-a-data-input-in-Server-GUI-that-modifies-the-inputs/m-p/443540#M77236</link>
    <description>&lt;P&gt;Thanks! Found it inside $SPLUNK_HOME\etc\apps\SplunkUniversalForwarder\local\inputs.conf&lt;/P&gt;</description>
    <pubDate>Fri, 13 Jul 2018 06:17:54 GMT</pubDate>
    <dc:creator>leantricity</dc:creator>
    <dc:date>2018-07-13T06:17:54Z</dc:date>
    <item>
      <title>How to add a data input in Server GUI that modifies the inputs.conf file in the Universal Forwarders?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-a-data-input-in-Server-GUI-that-modifies-the-inputs/m-p/443538#M77234</link>
      <description>&lt;P&gt;Hi:&lt;/P&gt;

&lt;P&gt;I'm using Splunk in a Mac OS X system. I've installed Universal Forwarders in several Windows Machines. I 've used the installer's GUI for the forwarders, customised the options to monitor a folder and data IS getting into Splunk Server. But when I check the Universal Forwarders etc/system/local/inputs.conf file I only see 2 lines [Default] and Host name. Nothing there about the directory I'm supposed to monitor in the server. As I've said, data IS getting into the server, but I get the "no source type for this job" error when trying to extract fields. So I was wondering if should I trust the GUI to add a Data Input for a Directory in the managed forwarders (they also show OK in the Server's console), or just tweak the inputs.conf file locally in each forwarder to add the source type field there.&lt;/P&gt;

&lt;P&gt;If I add a data input in the server GUI, is that configuration written anywhere in the remote universal forwarder ? &lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2018 23:29:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-a-data-input-in-Server-GUI-that-modifies-the-inputs/m-p/443538#M77234</guid>
      <dc:creator>leantricity</dc:creator>
      <dc:date>2018-07-12T23:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to add a data input in Server GUI that modifies the inputs.conf file in the Universal Forwarders?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-a-data-input-in-Server-GUI-that-modifies-the-inputs/m-p/443539#M77235</link>
      <description>&lt;P&gt;Hi leantricity,&lt;/P&gt;

&lt;P&gt;on the server with the universal forwarder you can run this command in the CLI:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; $SPLUNK_HOME\bin\splunk.exe btool inputs list --debug
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Where &lt;CODE&gt;$SPLUNK_HOME&lt;/CODE&gt; is the directory where you installed Splunk. The output of the command will show you the path and file where each option is configured.&lt;/P&gt;

&lt;P&gt;Hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2018 23:51:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-a-data-input-in-Server-GUI-that-modifies-the-inputs/m-p/443539#M77235</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2018-07-12T23:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to add a data input in Server GUI that modifies the inputs.conf file in the Universal Forwarders?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-a-data-input-in-Server-GUI-that-modifies-the-inputs/m-p/443540#M77236</link>
      <description>&lt;P&gt;Thanks! Found it inside $SPLUNK_HOME\etc\apps\SplunkUniversalForwarder\local\inputs.conf&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jul 2018 06:17:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-a-data-input-in-Server-GUI-that-modifies-the-inputs/m-p/443540#M77236</guid>
      <dc:creator>leantricity</dc:creator>
      <dc:date>2018-07-13T06:17:54Z</dc:date>
    </item>
  </channel>
</rss>

