All Apps and Add-ons

Splunk for unix: Do we need to edit ALL inputs.conf files?

ylsul
Explorer

Or is it enough just to do this on the indexer? I'm in the midst of fine-tuning things, and it would be great if I could alter timing intervals and what is being monitored from just one place. I saw this question asked before, but the answer was painfully ambiguous.

0 Karma

araitz
Splunk Employee
Splunk Employee

Not sure which question/answer you are referring to.

You need to alter the interval and toggle enabled/disabled where ever the inputs are being collected, most likely on the forwarder.

Have you looked at the Splunk Deployment Server?

http://docs.splunk.com/Documentation/Splunk/5.0.3/Deploy/Aboutdeploymentserver

0 Karma
Get Updates on the Splunk Community!

Now Playing: Splunk Education Summer Learning Premieres

It’s premiere season, and Splunk Education is rolling out new releases you won’t want to miss. Whether you’re ...

The Visibility Gap: Hybrid Networks and IT Services

The most forward thinking enterprises among us see their network as much more than infrastructure – it's their ...

Get Operational Insights Quickly with Natural Language on the Splunk Platform

In today’s fast-paced digital world, turning data into actionable insights is essential for success. With ...