Getting Data In

What deployment apps subdirectory on a Linux Deployment Server do I need to update inputs.conf and outputs.conf on a Windows Universal Forwarder?

OldManEd
Builder

I'm trying to follow the Splunk documentation to set up my Splunk Linux Deployment Server to update configuration files for my Windows servers using the Splunk Forwarder. Specifically, I would like to update the C:\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf and outputs.conf files automatically when needed from the Linux deployment server. Looking at the documentation example, it appears that they are asking to create the following directory on the deployment server to accomplish this; $SPLUNK_HOME/etc/deployment-apps/<deployment app name>/default/inputs.conf.

My question is, is this correct? I thought changing any files in any app under the "default" sub-directory was an incorrect procedure. Also, on the Windows forwarder, the listing under the C:\Program Files\SplunkUniversalForwarder\etc\apps\ is;

introspection_generator_addon
learned
search
splunk_httpinput
Splunk_TA_windows
SplunkUniversalForwarder

The inputs.conf and outputs.conf files that I need to update are not in these sub-directories. They are in C:\Program Files\SplunkUniversalForwarder\etc\system\local.

My question is, what "deployment-apps" sub-directory do I need to create and configure to make sure I'm updating the correct inputs.conf and outputs.conf files on my forwarder?

Thanks to all in advance.

0 Karma
1 Solution

OldManEd
Builder

This question is no longer valid. It was superseded by "Splunk Linux Deployment Server and the Windows Universal Forwarder Configuration Question". Sorry for the confusion. I can't figure out how to delete it.

View solution in original post

0 Karma

OldManEd
Builder

This question is no longer valid. It was superseded by "Splunk Linux Deployment Server and the Windows Universal Forwarder Configuration Question". Sorry for the confusion. I can't figure out how to delete it.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...