Archive

Help configuring forwarder on Windows 2008R2 for DHCP & RADIUS logs

New Member

I am attempting to add the DHCP and RADIUS logs on a server installed with the Splunk Forwarder.

I have the following configured within C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkTAwindows\local\input.conf and restarted the forwarder service.

###### DHCP ######
[monitor://C:\Windows\System32\DHCP]
disabled = false
whitelist = Dhcp*.log
crcSalt = <SOURCE>
sourcetype = Dhcp
alwaysOpenFile = 1

###### RADIUS ######
[monitor://C:\Windows\System32\LogFiles]
disabled = false
whitelist = IN*.log
crcSalt = <SOURCE>
sourcetype = RADIUS
alwaysOpenFile = 1

I cannot see any of that data within Splunk. What am I missing?

0 Karma

New Member

Just this command in input.conf

DHCP

[monitor://C:\Windows\System32\DHCP\Dhcp*.log]
disabled = 0

0 Karma

New Member

You might still have an other inputs.cong file taking precedence over the one you listed above. Check /system/local and any other apps.

0 Karma

Builder

make disabled = 0 & see the results.

0 Karma