Getting Data In

Is it possible to modify inputs.conf on our Windows universal forwarders via serverclass.conf using the deployment server?

mjesudasan
New Member

Hi,

I am trying to manage the universal forwarders on all our Windows system using the deployment server. They all have the same app (splunk_TA_windows) but the inputs.conf are all different on each server. Is it possible to manage this via serverclass.conf?

For example:

server 1 inputs.conf:

[WinEventLog://Application]
disabled = 0
start_from = oldest
current_only = 0
index = main
host =develop

server 2 inputs.conf:

[WinEventLog://Application]
disabled = 0
start_from = oldest
current_only = 0
index = main
host =staging

Thanks,
Milan

0 Karma

woodcock
Esteemed Legend

I would create a "splunk_TA_Windows_hostoverride" app and use IP-based stanzas in props.conf to override the hosts as necessary after the fact.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...