All Apps and Add-ons

Do I have to configure inputs.conf when adding the forwarder to a new linux machine?

djonesax
Engager

Hi,

We have installed the Splunk indexing server and webUI on a server along with the "App for Unix and Linux" and the "Add-on for Unix and Linux". We have also installed the universal forwarder and the "Add-on for Unix & Linux".

When we add the forwarder and add-on to the client machine, we have to manually enable the metrics and logs in the inputs.conf file before the forwarder will send any data to the indexer. We will not get any data at all until doing this as all the metrics in the inputs.conf file are "disabled". I was under the impression that the app and add-on were supposed to this automatically based on what logs and scripts are enabled in the WebUI.

Is this assumption correct, or is all this manual configuration neccessary?

Thanks,

David

pmdba
Builder

I believe that the UI only controls what is collected on the local indexing server or search head where it is installed. It does not configure distributed apps directly. If you configure the add-on as a distributed app you can change the inputs.conf file on your distribution server (one place) and push it out to all your remote forwarders that way.

Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...