All Apps and Add-ons

Do I have to configure inputs.conf when adding the forwarder to a new linux machine?

djonesax
Engager

Hi,

We have installed the Splunk indexing server and webUI on a server along with the "App for Unix and Linux" and the "Add-on for Unix and Linux". We have also installed the universal forwarder and the "Add-on for Unix & Linux".

When we add the forwarder and add-on to the client machine, we have to manually enable the metrics and logs in the inputs.conf file before the forwarder will send any data to the indexer. We will not get any data at all until doing this as all the metrics in the inputs.conf file are "disabled". I was under the impression that the app and add-on were supposed to this automatically based on what logs and scripts are enabled in the WebUI.

Is this assumption correct, or is all this manual configuration neccessary?

Thanks,

David

pmdba
Builder

I believe that the UI only controls what is collected on the local indexing server or search head where it is installed. It does not configure distributed apps directly. If you configure the add-on as a distributed app you can change the inputs.conf file on your distribution server (one place) and push it out to all your remote forwarders that way.

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...