Getting Data In

In a Windows forwarder install, I specified a log directory to monitor. Which inputs.conf does that get written in?

dvietze
New Member

During the Windows forwarder install I specified a path to monitor, and it is working, but it isn't in /splunk_home/etc/system default or local inputs.conf. Where is it? Thanks!

0 Karma

krish3
Contributor

If you added inputs from splunk home then it should be in

$SPLUNK_HOME/etc/apps/launcher/local/inputs.conf

If you added inputs from search and reporting app then it should be in

$SPLUNK_HOME/etc/apps/search/local/inputs.conf

else if you didnt get it still... You should be able to see the inputs by executing below command from splunk CLI.

splunk cmd btool inputs list monitor
0 Karma

harsmarvania57
Ultra Champion

Check in $SPLUNK_HOME/etc/apps/app name/default/inputs.conf OR $SPLUNK_HOME/etc/apps/app name/local/inputs.conf

I think app name starts with MSI but I am not sure.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...