We have recently been deploying the Splunk forwarder via command line through a 3rd part patching solution and setting the flags for which Windows Event logs to monitor. With the new patching solution we are using, it will not take enough characters for all the flags we want to set so we want to apply these flags/logs via a deployment-app. Could anybody give me a directory structure for the app, I know the path for the inputs.conf that it creates during installation is C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local. Can I just create another app with the correct inputs.conf file in it under local and will that supersede the one in the SplunkUniversalForwarder\local app?
Hi,
If you are creating an app, it will store under /etc/apps. Inside local directory whatever conf file you have mentioned and it will applicable only for the particular app.
You have asked directory structure for an app. Please refer the below link.
https://dev.splunk.com/enterprise/docs/developapps/createapps/createsplunkapp/
I know how to create deployment-apps. What I want to know is if there is a way to over-write C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local\inputs.conf with a deployment app since this file is normally created during installation of the UF? In other words, can I deploy an app from C:\Program Files\Splunk\etc\deployment-apps\SplunkUniversalForwarder\local\inputs.conf and have it overwrite the self generated file at C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local\inputs.conf?