All Apps and Add-ons

missing \local\inputs.conf file

HMTODD
Explorer

I used the rest API Modular Input form to create a new input. I can see the input in the Web UI and I can edit. I thought the configuration would be saved to inputs.conf but I cannot find this file. Do I need to create /local/inputs.conf or is the input configuration being saved elsewhere?

Tags (1)
0 Karma
1 Solution

sbbadri
Motivator

you can get inputs.conf from this location

$SPLUNK_HOME$/etc/apps/rest_ta/local/inputs.conf

or

$SPLUNK_HOME$/etc/apps/search/local/inputs.conf

View solution in original post

0 Karma

sbbadri
Motivator

you can get inputs.conf from this location

$SPLUNK_HOME$/etc/apps/rest_ta/local/inputs.conf

or

$SPLUNK_HOME$/etc/apps/search/local/inputs.conf

0 Karma

HMTODD
Explorer

There is no folder $SPLUNK_HOME$/etc/apps/rest_ta/local/inputs.conf. The inputs.conf located at $SPLUNK_HOME$/etc/apps/search/local/inputs.conf does not contain any of the modular inputs settings created for the Rest TA .

0 Karma

sbbadri
Motivator

ah okay,
From GUI, settings->Data inputs-> REST. It will have one table. Check under "App" column corresponding to your rest inputs.

$SPLUNk_HOME$/etc/app/app shown in the tabluar column/local/

0 Karma

HMTODD
Explorer

OK, so I can see the modular input in the Web UI at settings->Data inputs - >REST. In teh table presenting the app names is "launcher". When I look in $SPLUNK_HOME$/etc/apps/launcher/local/inputs.conf - Aha - there are my input settings.

Thanks!

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...