Hi,
I've recognized that my modularinput configuration for "myapp" has a strange situation.
When I am in Splunk using "myapp" and go to Data Inputs>MyAppInput, the inputs.conf file gets written properly (<myapp>/local/inputs.conf).
But when someone is in another app than "myapp" (e.g. search), and goes to Data Inputs>MyAppInput, the data gets written to /search/local/inputs.conf (not "myapp" app).
It gets written to the application folder from where you click on "Data Inputs".
How can i make sure that from wherever the user clicks on " Data Inputs>MyAppInput", the data gets only written in (<myapp>/local/inputs.conf)?
Thanks!
That’s Splunk Enterprise default behavior.
otherwise splunk doesn’t know where to write custom configurations.