All Apps and Add-ons

Newbie question on installing TA add-on for Windows

SLowry
New Member

I've downloaded TA for Windows & un-zipped it. (I downloaded the previous version, due to the message on the 4.5 edition not working with the Windows app.) I'm trying to manually install/enable it for use with the Universal Forwarder.

The Universal Forwarder installed in C:\Program Files\SplunkUniversalFowarder. Should this be moved to c:\program Files\Splunk?

I created C:\Splunk\etc\apps, where I copied the unzipped folder (Splunk_TA_windows). I created a folder in there named Local. I copied the inputs.config from the default folder to the Local folder.

Now I'm trying to edit the file to enable various data events. When I open the file in NotePad, it's just one/two long lines of data. Should I format the file in any way, or just leave it as is? Seems to me it needs formatting, but how & where I don't know. This is an example from the file to demonstrate my point:

    [WinEventLog:Application]
    disabled = 0start_from = oldestcurrent_only = 1checkpoint
0 Karma

lguinn2
Legend

Splunk does not care where you install it - you could install it under C:\SLowry and it would work. However, once it is installed on Windows, wherever it is, don't move it. Splunk installs a service on a Universal Forwarder (UF) and that's why moving Splunk is a bad idea.

On a UF, the installation directory ($SPLUNK_HOME) defaults to
C:\Program Files\SplunkUniversalForwarder. (I think this is your case.) You don't need C:\Splunk\etc\apps. There will be a directory
C:\Program Files\SplunkUniversalForwarder\etc\apps - that's where the Splunk_TA_Windows directory should go. So you should move it there (local directory and all).

Finally, the configuration files appear to have nonstandard line endings for Windows. In text files, Linux ends lines with LF but Windows uses CRLF. All the files whose names end in .conf will be like this. Notepad will be confused, but I think Wordpad or Notepad++ will handle this correctly. I know that Komodo Edit (free version for Windows) will handle and convert line endings properly. There are other tools out there that will do the conversion as well.

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...