Getting Data In

How to configure inputs.conf monitoring on universal forwarders for multiple apps?

yanivamram
Path Finder

Hi,

I'm using a Splunk Universal Forwarder to monitor log files on various machines.
I would like to split the inputs.conf in a way that each of my applications will "contribute" its own inputs.conf file.

Like:
<Splunk Home>/etc/apps/<my app1>/local/inputs.conf
and
/etc/apps/<my app2>/local/inputs.conf

The problem is that, although I see the forwarder monitor my log files, I don't see it on the Splunk server 😞
I do see data from other monitored log files which are configured in <Splunk Home>/etc/apps/search/local/inputs.conf

What am I doing wrong?

Thanks in advance,

Yaniv

0 Karma

jensonthottian
Contributor

did you check your default folder for each app.

0 Karma

tskinnerivsec
Contributor

you can use the btool command to see which inputs.conf directives are applied on your Universal forwarder:

splunk btool list inputs

This will show you what stanzas from inputs.conf are currently being applied. To give more help, we would need to see a sample of the inputs.conf file that is working, along with the path to the conf file as well as the same information from one of your inputs.conf files that is not working as expected.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...