Getting Data In

Deployed Inputs.conf Doesn't Work but system/local does?

stevepraz
Path Finder

Looking for a little help after fooling around with this for awhile. I have several forwarders on Windows and a Windows deployment server. The forwarders are installed with a configuration to point to the deployment server and they are successfully pulling down an app with outputs.conf that points them to the right indexers. This is working as I see the splunkd logs for each one coming in.

Today I started working on an app to deploy an inputs.conf file to enable event log monitoring. Here is the contents of the file:

[WinEventLog://Application]
index=wineventlog
disabled=0

[WinEventLog://Security]
index=wineventlog
disabled=0

[WinEventLog://System]
index=wineventlog
disabled=0

The app gets deployed successfully and the forwarders restart themselves but no data comes in. I removed the app from one of the forwarders and put the same stanzas above into the system/local/inputs.conf and bounced and it started working ok.

I can't figure out why the deployed version would work. These forwarders are stock, with no other custom apps (besides the output.conf). I've read through the config precedence document and can't see any place that something else would be overriding the inputs.conf in the custom app.

Any ideas?

0 Karma
1 Solution

stevepraz
Path Finder

Sorry about that... realized my silly mistake. In the more recent app structure, I created "defaults" rather than "default". After I renamed, things seem to be working.

View solution in original post

0 Karma

stevepraz
Path Finder

Sorry about that... realized my silly mistake. In the more recent app structure, I created "defaults" rather than "default". After I renamed, things seem to be working.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...