Getting Data In

Manual Inputs, what location are they kept?

_z_
Explorer

Not new to Splunk, but new to 4.2.2.
I had setup a forwarder and manually entered specific paths to monitor:

/p01/foo/bar/logs/server.log
/p02/foo/bar/logs/server.log
went to on to p50.

I just wanted to get Splunk 'working'.
I looked in the local/inputs.conf but the information was not there. So where is it kept?

I have to ask because I removed the above, edited ../local/inputs.conf and added:

[monitor:/p*/foo/bar/logs]
index = default
ignoreOlderThan = 3d

As I wanted to index all the logs within the 'logs' dir.

Now it appears the forwarder is not sending OR the indexer is no longer indexing. I am guessing the original configuration is kept someplace and messing up my ../local/inputs.conf

Any ideas?

1 Solution

_z_
Explorer
$ find . -name inputs.conf -print
./splunk/etc/system/default/inputs.conf
./splunk/etc/system/local/inputs.conf
./splunk/etc/apps/launcher/local/inputs.conf
./splunk/etc/apps/SplunkLightForwarder/default/inputs.conf
./splunk/etc/apps/SplunkDeploymentMonitor/local/inputs.conf
./splunk/etc/apps/sample_app/default/inputs.conf
./splunk/etc/apps/unix/default/inputs.conf
./splunk/etc/apps/unix/local/inputs.conf
./splunk/etc/modules/distributedDeployment/classes/deployable/inputs.conf

The file I was looking for is in ../launcher/local/inputs.conf

I still have an issue with the indexing not working, but since this was my original question, I will mark it answered.

View solution in original post

_z_
Explorer
$ find . -name inputs.conf -print
./splunk/etc/system/default/inputs.conf
./splunk/etc/system/local/inputs.conf
./splunk/etc/apps/launcher/local/inputs.conf
./splunk/etc/apps/SplunkLightForwarder/default/inputs.conf
./splunk/etc/apps/SplunkDeploymentMonitor/local/inputs.conf
./splunk/etc/apps/sample_app/default/inputs.conf
./splunk/etc/apps/unix/default/inputs.conf
./splunk/etc/apps/unix/local/inputs.conf
./splunk/etc/modules/distributedDeployment/classes/deployable/inputs.conf

The file I was looking for is in ../launcher/local/inputs.conf

I still have an issue with the indexing not working, but since this was my original question, I will mark it answered.

kristian_kolb
Ultra Champion

Hm, and the monitor command takes a few more slashes (assuming that this is your actual conf)

Suggest you try

[monitor://]

and remember that the path might start with an additional slash...

Hope this helps.

/Kristian

0 Karma

_z_
Explorer

Kristian,

Yep, I tried the '///' in front as well.. no joy.

Thanks!

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi z

how did you entered the paths to monitor? if it was over the 'webUI / Manager' it will propably end up in etc/apps/search/local.

and keep reading

regards

_z_
Explorer

MuS, just wanted to followup. I have another forwarder which I also setup manually via the Manager UI ... The etc/app/search/local dir does not exist...

So still looking for where these are kept.

0 Karma

_z_
Explorer

MuS,
I checked the path... the inputs.conf there is empty, which is correct since I removed all the entries I made.

I had reviewed that document you provided before... maybe I have to re-re-read...

0 Karma

_z_
Explorer

Yes, the original inputs were via the webUI/Manager...

I will check out the path, thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...