Getting Data In

Using "btool inpust list" monitor stanza is missing, but not when using "btool -app=xx inputs list"

rune_hellem
Contributor

Using command splunk btool --app=operations_inputs_prod inputs list the following is listed

[monitor://D:\logs\powershell\*.log]
index = klpoperations
sourcetype = log4net
whitelist = .*\.log

But if I try the command without the --app to list all configuraitons, the one above is missing, but not the three others in the file, and I'm not able to figure out why. I have tried a lot of different things, reloading the deploy-server a lot of times.

splunk btool inputs list
0 Karma

koshyk
Super Champion

Best thing is to do is to use debug , so you know exactly which APP the stanza is coming from. Then you can do app specific btool

splunk cmd btool inputs list debug > /tmp/inputs.btool.txt

you should see each line, which app it belongs to..

0 Karma

rune_hellem
Contributor

Well, it provides all details about the stanzas that the forwarder is configured to use, but still it won't explain why the one stanza is not part of the output, but the three others are.

It is worth mentioning that there are other inputs.conf for other indexes on the same server which are identical and are to be found in the config. So it should not be anything wrong with the missing stanza, they are identical.

0 Karma

ddrillic
Ultra Champion

On which server are you running the btool command, the forwarder or the deployment server?

0 Karma

rune_hellem
Contributor

On the forwarder...

0 Karma
Get Updates on the Splunk Community!

Sending Metrics to Splunk Enterprise With the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...

Want a chance to win $500 to the Splunk shop? Take our IT Incident Management Survey!

  Top Trends & Best Practices in Incident ManagementSplunk is partnering up with Constellation Research to ...