Getting Data In

In a Windows forwarder install, I specified a log directory to monitor. Which inputs.conf does that get written in?

dvietze
New Member

During the Windows forwarder install I specified a path to monitor, and it is working, but it isn't in /splunk_home/etc/system default or local inputs.conf. Where is it? Thanks!

0 Karma

krish3
Contributor

If you added inputs from splunk home then it should be in

$SPLUNK_HOME/etc/apps/launcher/local/inputs.conf

If you added inputs from search and reporting app then it should be in

$SPLUNK_HOME/etc/apps/search/local/inputs.conf

else if you didnt get it still... You should be able to see the inputs by executing below command from splunk CLI.

splunk cmd btool inputs list monitor
0 Karma

harsmarvania57
Ultra Champion

Check in $SPLUNK_HOME/etc/apps/app name/default/inputs.conf OR $SPLUNK_HOME/etc/apps/app name/local/inputs.conf

I think app name starts with MSI but I am not sure.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...