Getting Data In

Custom inputs.conf files in distributed architecture

lball
Explorer

We are using a distributed architecture and I have a couple of servers with custom windows logs that we want to pull into Splunk. I added the needed configs to the inputs.conf file, but periodically the custom inputs.conf files are being overwritten with the universally distributed conf file. How can I prevent this from happening? Or should I just add the custom configs to the core inputs.conf file that gets pushed out to the whole environment?

0 Karma
1 Solution

renjith_nair
Legend

Hi @lball,

You shall put them in an app and push to the respective servers. If you are using a deployment server to push the configs , then you could use serverclass to distinguish between the servers [https://docs.splunk.com/Documentation/Splunk/7.1.1/Updating/Useserverclass.conf] . Or you shall put them into the local directory of splunk to get a higher precedence. Have a look at the following link for more information about config file precedence http://docs.splunk.com/Documentation/Splunk/7.1.1/Admin/Wheretofindtheconfigurationfiles

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

renjith_nair
Legend

Hi @lball,

You shall put them in an app and push to the respective servers. If you are using a deployment server to push the configs , then you could use serverclass to distinguish between the servers [https://docs.splunk.com/Documentation/Splunk/7.1.1/Updating/Useserverclass.conf] . Or you shall put them into the local directory of splunk to get a higher precedence. Have a look at the following link for more information about config file precedence http://docs.splunk.com/Documentation/Splunk/7.1.1/Admin/Wheretofindtheconfigurationfiles

---
What goes around comes around. If it helps, hit it with Karma 🙂
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...