All Apps and Add-ons

Splunk for unix: Do we need to edit ALL inputs.conf files?

ylsul
Explorer

Or is it enough just to do this on the indexer? I'm in the midst of fine-tuning things, and it would be great if I could alter timing intervals and what is being monitored from just one place. I saw this question asked before, but the answer was painfully ambiguous.

0 Karma

araitz
Splunk Employee
Splunk Employee

Not sure which question/answer you are referring to.

You need to alter the interval and toggle enabled/disabled where ever the inputs are being collected, most likely on the forwarder.

Have you looked at the Splunk Deployment Server?

http://docs.splunk.com/Documentation/Splunk/5.0.3/Deploy/Aboutdeploymentserver

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with William Searle

The Splunk Guy: A Developer’s Path from Web to Cloud William is a Splunk Professional Services Consultant with ...

Major Splunk Upgrade – Prepare your Environment for Splunk 10 Now!

Attention App Developers: Test Your Apps with the Splunk 10.0 Beta and Ensure Compatibility Before the ...

Stay Connected: Your Guide to June Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...