Deployment Architecture

Deployment Server App Confusion

knutsod
Path Finder

I created a deployment app, lets call it windows. Inisde Windows\Local\ I have an input.conf and an outputs.conf file. My input.conf file looks like this:

[WinEventLog:Security]
disabled = flase

When the app gets delived to the clients (Windows Universal Forwarders) the input.conf file in the deployed app looks like this:

[WinEventLog://Security]
disabled = 1

What the heck is going on?

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

You may have a typo, flase instead of false.

Nonetheless, the inputs.conf reference suggests 0 or 1 as values. http://docs.splunk.com/Documentation/Splunk/6.1.1/admin/inputsconf

View solution in original post

knutsod
Path Finder

False was spelled wrong, thanks to martin_mueller for pointing that out.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You may have a typo, flase instead of false.

Nonetheless, the inputs.conf reference suggests 0 or 1 as values. http://docs.splunk.com/Documentation/Splunk/6.1.1/admin/inputsconf

martin_mueller
SplunkTrust
SplunkTrust

I'm sure you could build a Splunk alert that tells users to take a break if they've been Splunking along for more than X hours...

0 Karma

knutsod
Path Finder

That was it... I feel stupid. I think I need to step away from my desk and get some air. Thanks!

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...