All Apps and Add-ons

App to populate inputs.conf for Windows logs

rfiscus
Path Finder

We have recently been deploying the Splunk forwarder via command line through a 3rd part patching solution and setting the flags for which Windows Event logs to monitor. With the new patching solution we are using, it will not take enough characters for all the flags we want to set so we want to apply these flags/logs via a deployment-app. Could anybody give me a directory structure for the app, I know the path for the inputs.conf that it creates during installation is C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local. Can I just create another app with the correct inputs.conf file in it under local and will that supersede the one in the SplunkUniversalForwarder\local app?

Tags (1)
0 Karma

kartm2020
Communicator

Hi,

If you are creating an app, it will store under /etc/apps. Inside local directory whatever conf file you have mentioned and it will applicable only for the particular app.
You have asked directory structure for an app. Please refer the below link.

https://dev.splunk.com/enterprise/docs/developapps/createapps/createsplunkapp/

0 Karma

rfiscus
Path Finder

I know how to create deployment-apps. What I want to know is if there is a way to over-write C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local\inputs.conf with a deployment app since this file is normally created during installation of the UF? In other words, can I deploy an app from C:\Program Files\Splunk\etc\deployment-apps\SplunkUniversalForwarder\local\inputs.conf and have it overwrite the self generated file at C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local\inputs.conf?

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...