All Apps and Add-ons

Will the File/Directory Information Input add-on work on a universal forwarder?

a212830
Champion

Does the File/Directory app require a heavy forwarder? It appears to require python.

0 Karma
1 Solution

LukeMurphey
Champion

It does require a heavy forwarder. However, version 1.1 is being designed to eliminate the need for Splunk's Python and will work with the system's Python. See http://lukemurphey.net/issues/1068.

Note that this would still require Python on the host's system.

View solution in original post

sloshburch
Ultra Champion

Don't forget about the fschange stanza available in basic splunk.
http://docs.splunk.com/Documentation/Splunk/6.3.0/admin/Inputsconf

Of course, I assume you already know this and need something more advanced, otherwise @LukeMurphey wouldn't have written his app.

0 Karma

LukeMurphey
Champion

Part of the reason that this app exists is because fschange has been deprecated since 2012 (if I recall correctly). The input is going to be supported as long as Splunk 4.3 is supported; it might be removed then.

0 Karma

LukeMurphey
Champion

It does require a heavy forwarder. However, version 1.1 is being designed to eliminate the need for Splunk's Python and will work with the system's Python. See http://lukemurphey.net/issues/1068.

Note that this would still require Python on the host's system.

worshamn
Contributor

Now that this is at Version 1.2, will it now work on a universal forwarder? I have tried unsuccessfully to install it on a UF, but just wanted to make sure that it should or should not work.

0 Karma

LukeMurphey
Champion

As of version 1.3, it does support Universal Forwarder provided the host has Python available (Python 2.7 is recommended).

Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...