Deployment Architecture

Deployment Server App Confusion

knutsod
Path Finder

I created a deployment app, lets call it windows. Inisde Windows\Local\ I have an input.conf and an outputs.conf file. My input.conf file looks like this:

[WinEventLog:Security]
disabled = flase

When the app gets delived to the clients (Windows Universal Forwarders) the input.conf file in the deployed app looks like this:

[WinEventLog://Security]
disabled = 1

What the heck is going on?

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

You may have a typo, flase instead of false.

Nonetheless, the inputs.conf reference suggests 0 or 1 as values. http://docs.splunk.com/Documentation/Splunk/6.1.1/admin/inputsconf

View solution in original post

knutsod
Path Finder

False was spelled wrong, thanks to martin_mueller for pointing that out.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You may have a typo, flase instead of false.

Nonetheless, the inputs.conf reference suggests 0 or 1 as values. http://docs.splunk.com/Documentation/Splunk/6.1.1/admin/inputsconf

martin_mueller
SplunkTrust
SplunkTrust

I'm sure you could build a Splunk alert that tells users to take a break if they've been Splunking along for more than X hours...

0 Karma

knutsod
Path Finder

That was it... I feel stupid. I think I need to step away from my desk and get some air. Thanks!

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...