Getting Data In

Is it possible to modify inputs.conf on our Windows universal forwarders via serverclass.conf using the deployment server?

mjesudasan
New Member

Hi,

I am trying to manage the universal forwarders on all our Windows system using the deployment server. They all have the same app (splunk_TA_windows) but the inputs.conf are all different on each server. Is it possible to manage this via serverclass.conf?

For example:

server 1 inputs.conf:

[WinEventLog://Application]
disabled = 0
start_from = oldest
current_only = 0
index = main
host =develop

server 2 inputs.conf:

[WinEventLog://Application]
disabled = 0
start_from = oldest
current_only = 0
index = main
host =staging

Thanks,
Milan

0 Karma

woodcock
Esteemed Legend

I would create a "splunk_TA_Windows_hostoverride" app and use IP-based stanzas in props.conf to override the hosts as necessary after the fact.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...