All Apps and Add-ons

App to populate inputs.conf for Windows logs

rfiscus
Path Finder

We have recently been deploying the Splunk forwarder via command line through a 3rd part patching solution and setting the flags for which Windows Event logs to monitor. With the new patching solution we are using, it will not take enough characters for all the flags we want to set so we want to apply these flags/logs via a deployment-app. Could anybody give me a directory structure for the app, I know the path for the inputs.conf that it creates during installation is C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local. Can I just create another app with the correct inputs.conf file in it under local and will that supersede the one in the SplunkUniversalForwarder\local app?

Tags (1)
0 Karma

kartm2020
Communicator

Hi,

If you are creating an app, it will store under /etc/apps. Inside local directory whatever conf file you have mentioned and it will applicable only for the particular app.
You have asked directory structure for an app. Please refer the below link.

https://dev.splunk.com/enterprise/docs/developapps/createapps/createsplunkapp/

0 Karma

rfiscus
Path Finder

I know how to create deployment-apps. What I want to know is if there is a way to over-write C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local\inputs.conf with a deployment app since this file is normally created during installation of the UF? In other words, can I deploy an app from C:\Program Files\Splunk\etc\deployment-apps\SplunkUniversalForwarder\local\inputs.conf and have it overwrite the self generated file at C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local\inputs.conf?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...