All Apps and Add-ons

App to populate inputs.conf for Windows logs

rfiscus
Path Finder

We have recently been deploying the Splunk forwarder via command line through a 3rd part patching solution and setting the flags for which Windows Event logs to monitor. With the new patching solution we are using, it will not take enough characters for all the flags we want to set so we want to apply these flags/logs via a deployment-app. Could anybody give me a directory structure for the app, I know the path for the inputs.conf that it creates during installation is C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local. Can I just create another app with the correct inputs.conf file in it under local and will that supersede the one in the SplunkUniversalForwarder\local app?

Tags (1)
0 Karma

kartm2020
Communicator

Hi,

If you are creating an app, it will store under /etc/apps. Inside local directory whatever conf file you have mentioned and it will applicable only for the particular app.
You have asked directory structure for an app. Please refer the below link.

https://dev.splunk.com/enterprise/docs/developapps/createapps/createsplunkapp/

0 Karma

rfiscus
Path Finder

I know how to create deployment-apps. What I want to know is if there is a way to over-write C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local\inputs.conf with a deployment app since this file is normally created during installation of the UF? In other words, can I deploy an app from C:\Program Files\Splunk\etc\deployment-apps\SplunkUniversalForwarder\local\inputs.conf and have it overwrite the self generated file at C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local\inputs.conf?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...