Getting Data In

How do I define a stanza that applies to all stanzas in the same inputs.conf file?

neiljpeterson
Communicator

I could have sworn it was [] but that did not seem to work, nor did [*]

I do not want to use [default] because I don't want to change all inputs on the host, just the ones in a given file.

I could swear I've seen this done, and it should be easy but I searched and searched to no avail.

Please help!

0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

This is not the way it works, they are no notion stanza limited to a single inputs.conf or a single app.

The parameter are specific to their specific stanza.
The only exception is the [default] that is for all stanza (in all the apps)

Maybe are you confused with the props.conf that may overlap.

See the way splunk configuration merges, and use btool to verify :

http://docs.splunk.com/Documentation/Splunk/latest/Admin/Wheretofindtheconfigurationfiles
http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Usebtooltotroubleshootconfigurati...

View solution in original post

yannK
Splunk Employee
Splunk Employee

This is not the way it works, they are no notion stanza limited to a single inputs.conf or a single app.

The parameter are specific to their specific stanza.
The only exception is the [default] that is for all stanza (in all the apps)

Maybe are you confused with the props.conf that may overlap.

See the way splunk configuration merges, and use btool to verify :

http://docs.splunk.com/Documentation/Splunk/latest/Admin/Wheretofindtheconfigurationfiles
http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Usebtooltotroubleshootconfigurati...

neiljpeterson
Communicator

Oh. Well then. 😕

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...