<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: inputs.conf not being processed- Windows in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-not-being-processed-Windows/m-p/88763#M97267</link>
    <description>&lt;P&gt;Well, I was just guessing as to why the config did not list. Anyway, I would still suggest that you deploy one app for the DC's and another app for the other Windows hosts.&lt;/P&gt;

&lt;P&gt;Neat and simple, with little room for confusion.&lt;/P&gt;

&lt;P&gt;/K&lt;/P&gt;</description>
    <pubDate>Tue, 08 Oct 2013 20:26:55 GMT</pubDate>
    <dc:creator>kristian_kolb</dc:creator>
    <dc:date>2013-10-08T20:26:55Z</dc:date>
    <item>
      <title>inputs.conf not being processed- Windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-not-being-processed-Windows/m-p/88760#M97264</link>
      <description>&lt;P&gt;I would like to have all Windows servers send all their event logs to my "windows" index, except for the domain controllers. For those, I want just the Security event log to go to the "AD" index. The forwarders are being controlled via a deployment server. I have two inputs.conf files in their own \apps\ directories, but only 1 is being used and even appearing in the "splunk cmd btool inputs list --debug" output. &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;C:\Program Files\SplunkUniversalForwarder\etc\apps\ad\local\inputs.conf&lt;/STRONG&gt; &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;###### Active Directory "Security" event log ######
[WinEventLog://Security]
checkpointInterval = 5
current_only = 0
disabled = 0
index = ad
start_from = oldest
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\local\inputs.conf&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WinEventLog://Security]
checkpointInterval = 5
current_only = 0
disabled = 0
index = windows
start_from = oldest
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Currently all DC events are being sent to the "windows" index. Hurmph. I'm pretty sure this is set up correctly, as \ad\ comes before \Splunk_TA_windows\ alphabetically.  This behavior is identical across 4 different DCs. I cant seem to find any documentation about conf files being ignored totally and completely. Stumped.&lt;/P&gt;

&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:55:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-not-being-processed-Windows/m-p/88760#M97264</guid>
      <dc:creator>peterfilardo</dc:creator>
      <dc:date>2020-09-28T14:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: inputs.conf not being processed- Windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-not-being-processed-Windows/m-p/88761#M97265</link>
      <description>&lt;P&gt;Though I have not played a lot with configuration file precedence, i.e. knowingly distributed apps with conflicting configs, it seems that you are right in your assumptions. Is the 'ad' app enabled?&lt;BR /&gt;
See the app.conf for that app.&lt;/P&gt;

&lt;P&gt;Other solutions/workarounds;&lt;/P&gt;

&lt;P&gt;Why not create a separate serverclass for the DC's and create two different apps, where the value for the destination index is the major difference.?&lt;/P&gt;

&lt;P&gt;Or you can set up a index-time TRANSFORM to rewrite the destination index for the events coming from the DC's.&lt;/P&gt;

&lt;P&gt;/K&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2013 20:12:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-not-being-processed-Windows/m-p/88761#M97265</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-10-08T20:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: inputs.conf not being processed- Windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-not-being-processed-Windows/m-p/88762#M97266</link>
      <description>&lt;P&gt;the AD app is one of my own creation, the contents of which are local\inputs.conf. Is there a line I need to add to enable it? I'd have thought that app would be put in disabled-apps. I've created and distributed apps for other inputs.conf files and did not explictly enable them in the files, only within the "Forwarder Management" page of the deployment server.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2013 20:24:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-not-being-processed-Windows/m-p/88762#M97266</guid>
      <dc:creator>peterfilardo</dc:creator>
      <dc:date>2013-10-08T20:24:23Z</dc:date>
    </item>
    <item>
      <title>Re: inputs.conf not being processed- Windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-not-being-processed-Windows/m-p/88763#M97267</link>
      <description>&lt;P&gt;Well, I was just guessing as to why the config did not list. Anyway, I would still suggest that you deploy one app for the DC's and another app for the other Windows hosts.&lt;/P&gt;

&lt;P&gt;Neat and simple, with little room for confusion.&lt;/P&gt;

&lt;P&gt;/K&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2013 20:26:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-not-being-processed-Windows/m-p/88763#M97267</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-10-08T20:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: inputs.conf not being processed- Windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-not-being-processed-Windows/m-p/88764#M97268</link>
      <description>&lt;P&gt;This is a precedence problem, and a not-best-practice issue.&lt;BR /&gt;&lt;BR /&gt;
Uppercase S takes App precedence over lowercase a.  See:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/Wheretofindtheconfigurationfiles"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Admin/Wheretofindtheconfigurationfiles&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Kristian is right about different serverclasses because it is does not seem right to have conflicting enabled source inputs.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2013 20:30:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-not-being-processed-Windows/m-p/88764#M97268</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-10-08T20:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: inputs.conf not being processed- Windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-not-being-processed-Windows/m-p/88765#M97269</link>
      <description>&lt;P&gt;aah, of course. Uppercase comes before lowercase....&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2013 20:35:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-not-being-processed-Windows/m-p/88765#M97269</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-10-08T20:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: inputs.conf not being processed- Windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-not-being-processed-Windows/m-p/88766#M97270</link>
      <description>&lt;P&gt;uppercase before lower, UGH. totally should have caught that. works now, thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2013 23:17:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-not-being-processed-Windows/m-p/88766#M97270</guid>
      <dc:creator>peterfilardo</dc:creator>
      <dc:date>2013-10-08T23:17:53Z</dc:date>
    </item>
  </channel>
</rss>

