Getting Data In

Deployed Inputs.conf Doesn't Work but system/local does?

stevepraz
Path Finder

Looking for a little help after fooling around with this for awhile. I have several forwarders on Windows and a Windows deployment server. The forwarders are installed with a configuration to point to the deployment server and they are successfully pulling down an app with outputs.conf that points them to the right indexers. This is working as I see the splunkd logs for each one coming in.

Today I started working on an app to deploy an inputs.conf file to enable event log monitoring. Here is the contents of the file:

[WinEventLog://Application]
index=wineventlog
disabled=0

[WinEventLog://Security]
index=wineventlog
disabled=0

[WinEventLog://System]
index=wineventlog
disabled=0

The app gets deployed successfully and the forwarders restart themselves but no data comes in. I removed the app from one of the forwarders and put the same stanzas above into the system/local/inputs.conf and bounced and it started working ok.

I can't figure out why the deployed version would work. These forwarders are stock, with no other custom apps (besides the output.conf). I've read through the config precedence document and can't see any place that something else would be overriding the inputs.conf in the custom app.

Any ideas?

0 Karma
1 Solution

stevepraz
Path Finder

Sorry about that... realized my silly mistake. In the more recent app structure, I created "defaults" rather than "default". After I renamed, things seem to be working.

View solution in original post

0 Karma

stevepraz
Path Finder

Sorry about that... realized my silly mistake. In the more recent app structure, I created "defaults" rather than "default". After I renamed, things seem to be working.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...