<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: INPUTS.CONF in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/INPUTS-CONF/m-p/253429#M99194</link>
    <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;... or should i add that in the inputs.conf at the universal forwarder local level or ...&lt;BR /&gt;
This seems to be the right thing to do.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
    <pubDate>Mon, 21 Mar 2016 14:54:45 GMT</pubDate>
    <dc:creator>ddrillic</dc:creator>
    <dc:date>2016-03-21T14:54:45Z</dc:date>
    <item>
      <title>INPUTS.CONF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/INPUTS-CONF/m-p/253428#M99193</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;

&lt;P&gt;Beginner at splunk here, can I add custom stanzas to windows -add -on to collect server roles data, or should i add that in the &lt;BR /&gt;
inputs.conf at the  universal forwarder local level or to the inputs.conf file of the windows add on.?&lt;/P&gt;

&lt;P&gt;my aim is to just collect log files like IIS,certificate services and so on.&lt;/P&gt;

&lt;P&gt;q2. Inorder to monitor windows host information from other universal forwarders, do i have to intall splunk enterprise on windows only. &lt;BR /&gt;
      can i not intall it on ubuntu, forward the relevant data using universal forwarders to the splunk enterprise which is on windows ? &lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2016 11:41:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/INPUTS-CONF/m-p/253428#M99193</guid>
      <dc:creator>tejasplunk</dc:creator>
      <dc:date>2016-03-21T11:41:29Z</dc:date>
    </item>
    <item>
      <title>Re: INPUTS.CONF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/INPUTS-CONF/m-p/253429#M99194</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;... or should i add that in the inputs.conf at the universal forwarder local level or ...&lt;BR /&gt;
This seems to be the right thing to do.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Mon, 21 Mar 2016 14:54:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/INPUTS-CONF/m-p/253429#M99194</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-03-21T14:54:45Z</dc:date>
    </item>
  </channel>
</rss>

