Getting Data In

Using "btool inpust list" monitor stanza is missing, but not when using "btool -app=xx inputs list"

rune_hellem
Contributor

Using command splunk btool --app=operations_inputs_prod inputs list the following is listed

[monitor://D:\logs\powershell\*.log]
index = klpoperations
sourcetype = log4net
whitelist = .*\.log

But if I try the command without the --app to list all configuraitons, the one above is missing, but not the three others in the file, and I'm not able to figure out why. I have tried a lot of different things, reloading the deploy-server a lot of times.

splunk btool inputs list
0 Karma

koshyk
Super Champion

Best thing is to do is to use debug , so you know exactly which APP the stanza is coming from. Then you can do app specific btool

splunk cmd btool inputs list debug > /tmp/inputs.btool.txt

you should see each line, which app it belongs to..

0 Karma

rune_hellem
Contributor

Well, it provides all details about the stanzas that the forwarder is configured to use, but still it won't explain why the one stanza is not part of the output, but the three others are.

It is worth mentioning that there are other inputs.conf for other indexes on the same server which are identical and are to be found in the config. So it should not be anything wrong with the missing stanza, they are identical.

0 Karma

ddrillic
Ultra Champion

On which server are you running the btool command, the forwarder or the deployment server?

0 Karma

rune_hellem
Contributor

On the forwarder...

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...