Getting Data In

Deployed Inputs.conf Doesn't Work but system/local does?

stevepraz
Path Finder

Looking for a little help after fooling around with this for awhile. I have several forwarders on Windows and a Windows deployment server. The forwarders are installed with a configuration to point to the deployment server and they are successfully pulling down an app with outputs.conf that points them to the right indexers. This is working as I see the splunkd logs for each one coming in.

Today I started working on an app to deploy an inputs.conf file to enable event log monitoring. Here is the contents of the file:

[WinEventLog://Application]
index=wineventlog
disabled=0

[WinEventLog://Security]
index=wineventlog
disabled=0

[WinEventLog://System]
index=wineventlog
disabled=0

The app gets deployed successfully and the forwarders restart themselves but no data comes in. I removed the app from one of the forwarders and put the same stanzas above into the system/local/inputs.conf and bounced and it started working ok.

I can't figure out why the deployed version would work. These forwarders are stock, with no other custom apps (besides the output.conf). I've read through the config precedence document and can't see any place that something else would be overriding the inputs.conf in the custom app.

Any ideas?

0 Karma
1 Solution

stevepraz
Path Finder

Sorry about that... realized my silly mistake. In the more recent app structure, I created "defaults" rather than "default". After I renamed, things seem to be working.

View solution in original post

0 Karma

stevepraz
Path Finder

Sorry about that... realized my silly mistake. In the more recent app structure, I created "defaults" rather than "default". After I renamed, things seem to be working.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...