Getting Data In

In a Windows forwarder install, I specified a log directory to monitor. Which inputs.conf does that get written in?

dvietze
New Member

During the Windows forwarder install I specified a path to monitor, and it is working, but it isn't in /splunk_home/etc/system default or local inputs.conf. Where is it? Thanks!

0 Karma

krish3
Contributor

If you added inputs from splunk home then it should be in

$SPLUNK_HOME/etc/apps/launcher/local/inputs.conf

If you added inputs from search and reporting app then it should be in

$SPLUNK_HOME/etc/apps/search/local/inputs.conf

else if you didnt get it still... You should be able to see the inputs by executing below command from splunk CLI.

splunk cmd btool inputs list monitor
0 Karma

harsmarvania57
Ultra Champion

Check in $SPLUNK_HOME/etc/apps/app name/default/inputs.conf OR $SPLUNK_HOME/etc/apps/app name/local/inputs.conf

I think app name starts with MSI but I am not sure.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...