Getting Data In

Splunk forwarder config not working

amitj
New Member

since are trying to separate out splunk forwarder config ("inputs.conf") according to indexer. we defined forwarder conf like "/opt/splunkforwarder/etc/apps/IND1/inputs.conf", "/opt/splunkforwarder/etc/apps/IND2/inputs.conf" and restarted the splunk instance. but somehow it is not working..Do I need to define "IND1" and "IND2" as an app first?

Tags (1)
0 Karma

amitj
New Member

No, do I need to define outputs.conf for this?

0 Karma

jtworzydlo
Path Finder

Have you also defined outputs.conf for each config?

0 Karma

amitj
New Member

yes, I added to "local" directory like../opt/splunkforwarder/etc/apps/IND1/local/inputs.conf but it didn't work

0 Karma

Ayn
Legend

inputs.conf, like all other configuration files, need to be either in an app's default directory or its local directory. So, /opt/splunkforwarder/etc/apps/IND1/default/inputs.conf would work, for instance.

0 Karma

Ayn
Legend

OK, because that's not what it said in your question...anyhow, you shouldn't need to "activate" this anywhere, just restart the Splunk instance and you should be good to go. Possible steps forward is to check btool output ($SPLUNK_HOME/bin/splunk cmd btool inputs list --debug) to see if Splunk sees your defined inputs. If it does, you should check splunkd.log to see if there are any problems with the inputs you've defined.

0 Karma

amitj
New Member

yes, I added to "local" directory like../opt/splunkforwarder/etc/apps/IND1/local/inputs.conf but it didn't work

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...