Archive2
Highlighted

Splunk_TA_windows how to configure inputs.conf for specific targets?

Path Finder

I'm using SplunkTAwindows addon as a deployment app.

In the local/inputs.conf, I've added a stanza to monitor Windows Event Log where the channel does not exist on all the Windows computers where the SplunkTAwindows app is deployed.

This is causing errors in the splunkd.log.

It is possible to configure the inputs.conf for specific computers, or suppress error logging on inputs which are known not to exist on all computers?

Is the only answer to make another deployment app for the specific servers?

Tags (1)
0 Karma
Reply