Getting Data In

Manual Inputs, what location are they kept?

_z_
Explorer

Not new to Splunk, but new to 4.2.2.
I had setup a forwarder and manually entered specific paths to monitor:

/p01/foo/bar/logs/server.log
/p02/foo/bar/logs/server.log
went to on to p50.

I just wanted to get Splunk 'working'.
I looked in the local/inputs.conf but the information was not there. So where is it kept?

I have to ask because I removed the above, edited ../local/inputs.conf and added:

[monitor:/p*/foo/bar/logs]
index = default
ignoreOlderThan = 3d

As I wanted to index all the logs within the 'logs' dir.

Now it appears the forwarder is not sending OR the indexer is no longer indexing. I am guessing the original configuration is kept someplace and messing up my ../local/inputs.conf

Any ideas?

1 Solution

_z_
Explorer
$ find . -name inputs.conf -print
./splunk/etc/system/default/inputs.conf
./splunk/etc/system/local/inputs.conf
./splunk/etc/apps/launcher/local/inputs.conf
./splunk/etc/apps/SplunkLightForwarder/default/inputs.conf
./splunk/etc/apps/SplunkDeploymentMonitor/local/inputs.conf
./splunk/etc/apps/sample_app/default/inputs.conf
./splunk/etc/apps/unix/default/inputs.conf
./splunk/etc/apps/unix/local/inputs.conf
./splunk/etc/modules/distributedDeployment/classes/deployable/inputs.conf

The file I was looking for is in ../launcher/local/inputs.conf

I still have an issue with the indexing not working, but since this was my original question, I will mark it answered.

View solution in original post

_z_
Explorer
$ find . -name inputs.conf -print
./splunk/etc/system/default/inputs.conf
./splunk/etc/system/local/inputs.conf
./splunk/etc/apps/launcher/local/inputs.conf
./splunk/etc/apps/SplunkLightForwarder/default/inputs.conf
./splunk/etc/apps/SplunkDeploymentMonitor/local/inputs.conf
./splunk/etc/apps/sample_app/default/inputs.conf
./splunk/etc/apps/unix/default/inputs.conf
./splunk/etc/apps/unix/local/inputs.conf
./splunk/etc/modules/distributedDeployment/classes/deployable/inputs.conf

The file I was looking for is in ../launcher/local/inputs.conf

I still have an issue with the indexing not working, but since this was my original question, I will mark it answered.

kristian_kolb
Ultra Champion

Hm, and the monitor command takes a few more slashes (assuming that this is your actual conf)

Suggest you try

[monitor://]

and remember that the path might start with an additional slash...

Hope this helps.

/Kristian

0 Karma

_z_
Explorer

Kristian,

Yep, I tried the '///' in front as well.. no joy.

Thanks!

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi z

how did you entered the paths to monitor? if it was over the 'webUI / Manager' it will propably end up in etc/apps/search/local.

and keep reading

regards

_z_
Explorer

MuS, just wanted to followup. I have another forwarder which I also setup manually via the Manager UI ... The etc/app/search/local dir does not exist...

So still looking for where these are kept.

0 Karma

_z_
Explorer

MuS,
I checked the path... the inputs.conf there is empty, which is correct since I removed all the entries I made.

I had reviewed that document you provided before... maybe I have to re-re-read...

0 Karma

_z_
Explorer

Yes, the original inputs were via the webUI/Manager...

I will check out the path, thanks!

0 Karma
Get Updates on the Splunk Community!

Platform Highlights | November 2022 Newsletter

 November 2022 Skill Up on Splunk with our New Builder Tech Talk SeriesCan you build it? Yes you can! *play ...

Splunk Education - Fast Start Program!

Welcome to Splunk Education! Splunk training programs are designed to enable you to get started quickly and ...

Five Subtly Different Ways of Adding Manual Instrumentation in Java

You can find the code of this example on GitHub here. Please feel free to star the repository to keep in ...