All Apps and Add-ons

Did I format my Splunk Input.conf file for bamboo correctly?

nehannaidu
Engager

I have edited edited Input.conf file as below.

[Bamboo://localhost:8085]
sourcetype = bamboo
interval = 60
server = http://localhost:8085
protocol = https
port = 8085
username = bamboo_user
password = bamboo_pwd
disabled = 0

Is above file is correct?

Based on this HTTP event collector will generate the token in Splunk web enterprise right?

 

 

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The btool command will tell you if the file complies with the specs. 

splunk btool check

Correctness, however, is harder to define without knowing more about any add-ons these settings are for.  For example, should the port number be in the server attribute if it's also specified separately?  Protocol is "https", but the server value uses http.  This may or may not be a problem.

The stanza will not, however, generate a HEC token.  You should use the GUI (Settings->Data inputs->HTTP Event Collector) to generate a token and then put it into an [http://<<name>>] stanza in inputs.conf.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...