<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk - Adding stanza in input.conf file in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Adding-stanza-in-input-conf-file/m-p/475870#M81666</link>
    <description>&lt;P&gt;i am using Splunk enterprise trial version and trying to push the windows logs to Splunk from the customize location . I gave  the path location of my file which i want to push in /etc/system/local folder inside input.conf file and restarted the splunk server but still i could not able to see the file in splunk.&lt;BR /&gt;
I have followed the below documents to add the stanza in the input.conf file &lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.1/Data/Monitorfilesanddirectorieswithinputs.conf"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.1/Data/Monitorfilesanddirectorieswithinputs.conf&lt;/A&gt; &lt;/P&gt;

&lt;P&gt;Can anyone please guide me in this as how to push the file ti splunk from a customize location&lt;BR /&gt;
Note- I made the changes in the input.conf file inside splunk universal forwarder directory as i dont have $splunk_home file directory&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jan 2020 11:26:32 GMT</pubDate>
    <dc:creator>rajiv_r</dc:creator>
    <dc:date>2020-01-07T11:26:32Z</dc:date>
    <item>
      <title>Splunk - Adding stanza in input.conf file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Adding-stanza-in-input-conf-file/m-p/475870#M81666</link>
      <description>&lt;P&gt;i am using Splunk enterprise trial version and trying to push the windows logs to Splunk from the customize location . I gave  the path location of my file which i want to push in /etc/system/local folder inside input.conf file and restarted the splunk server but still i could not able to see the file in splunk.&lt;BR /&gt;
I have followed the below documents to add the stanza in the input.conf file &lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.1/Data/Monitorfilesanddirectorieswithinputs.conf"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.1/Data/Monitorfilesanddirectorieswithinputs.conf&lt;/A&gt; &lt;/P&gt;

&lt;P&gt;Can anyone please guide me in this as how to push the file ti splunk from a customize location&lt;BR /&gt;
Note- I made the changes in the input.conf file inside splunk universal forwarder directory as i dont have $splunk_home file directory&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2020 11:26:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Adding-stanza-in-input-conf-file/m-p/475870#M81666</guid>
      <dc:creator>rajiv_r</dc:creator>
      <dc:date>2020-01-07T11:26:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk - Adding stanza in input.conf file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Adding-stanza-in-input-conf-file/m-p/475871#M81667</link>
      <description>&lt;P&gt;Please post the inputs.conf settings for the logs and the search you are using to try to find the data.&lt;/P&gt;

&lt;P&gt;Every Splunk instance has a $SPLUNK_HOME directory.  It's the file system location where Splunk is installed.  On Windows systems with a UF installed, it's often &lt;CODE&gt;C:\Program Files\SplunkUniversalForwarder&lt;/CODE&gt;.  $SPLUNK_HOME is Linux notation for a shell variable.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:36:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Adding-stanza-in-input-conf-file/m-p/475871#M81667</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-09-30T03:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk - Adding stanza in input.conf file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Adding-stanza-in-input-conf-file/m-p/475872#M81668</link>
      <description>&lt;P&gt;again a lot of thanks for your answer  i got it fixed..Actually document was saying to restart the server but actually we need to restart the forwarder only. And when i did it it started working&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2020 12:22:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Adding-stanza-in-input-conf-file/m-p/475872#M81668</guid>
      <dc:creator>rajiv_r</dc:creator>
      <dc:date>2020-01-07T12:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk - Adding stanza in input.conf file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Adding-stanza-in-input-conf-file/m-p/475873#M81669</link>
      <description>&lt;P&gt;Please submit feedback (not a comment) on the documentation so Splunk can clarify what should be restarted.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2020 13:10:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Adding-stanza-in-input-conf-file/m-p/475873#M81669</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-01-07T13:10:50Z</dc:date>
    </item>
  </channel>
</rss>

