Getting Data In

Deployed Inputs.conf Doesn't Work but system/local does?

stevepraz
Path Finder

Looking for a little help after fooling around with this for awhile. I have several forwarders on Windows and a Windows deployment server. The forwarders are installed with a configuration to point to the deployment server and they are successfully pulling down an app with outputs.conf that points them to the right indexers. This is working as I see the splunkd logs for each one coming in.

Today I started working on an app to deploy an inputs.conf file to enable event log monitoring. Here is the contents of the file:

[WinEventLog://Application]
index=wineventlog
disabled=0

[WinEventLog://Security]
index=wineventlog
disabled=0

[WinEventLog://System]
index=wineventlog
disabled=0

The app gets deployed successfully and the forwarders restart themselves but no data comes in. I removed the app from one of the forwarders and put the same stanzas above into the system/local/inputs.conf and bounced and it started working ok.

I can't figure out why the deployed version would work. These forwarders are stock, with no other custom apps (besides the output.conf). I've read through the config precedence document and can't see any place that something else would be overriding the inputs.conf in the custom app.

Any ideas?

0 Karma
1 Solution

stevepraz
Path Finder

Sorry about that... realized my silly mistake. In the more recent app structure, I created "defaults" rather than "default". After I renamed, things seem to be working.

View solution in original post

0 Karma

stevepraz
Path Finder

Sorry about that... realized my silly mistake. In the more recent app structure, I created "defaults" rather than "default". After I renamed, things seem to be working.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...