Getting Data In

In a Windows forwarder install, I specified a log directory to monitor. Which inputs.conf does that get written in?

New Member

During the Windows forwarder install I specified a path to monitor, and it is working, but it isn't in /splunk_home/etc/system default or local inputs.conf. Where is it? Thanks!

0 Karma

Contributor

If you added inputs from splunk home then it should be in

$SPLUNK_HOME/etc/apps/launcher/local/inputs.conf

If you added inputs from search and reporting app then it should be in

$SPLUNK_HOME/etc/apps/search/local/inputs.conf

else if you didnt get it still... You should be able to see the inputs by executing below command from splunk CLI.

splunk cmd btool inputs list monitor
0 Karma

SplunkTrust
SplunkTrust

Check in $SPLUNK_HOME/etc/apps/app name/default/inputs.conf OR $SPLUNK_HOME/etc/apps/app name/local/inputs.conf

I think app name starts with MSI but I am not sure.

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!