Getting Data In

What deployment apps subdirectory on a Linux Deployment Server do I need to update inputs.conf and outputs.conf on a Windows Universal Forwarder?

OldManEd
Builder

I'm trying to follow the Splunk documentation to set up my Splunk Linux Deployment Server to update configuration files for my Windows servers using the Splunk Forwarder. Specifically, I would like to update the C:\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf and outputs.conf files automatically when needed from the Linux deployment server. Looking at the documentation example, it appears that they are asking to create the following directory on the deployment server to accomplish this; $SPLUNK_HOME/etc/deployment-apps/<deployment app name>/default/inputs.conf.

My question is, is this correct? I thought changing any files in any app under the "default" sub-directory was an incorrect procedure. Also, on the Windows forwarder, the listing under the C:\Program Files\SplunkUniversalForwarder\etc\apps\ is;

introspection_generator_addon
learned
search
splunk_httpinput
Splunk_TA_windows
SplunkUniversalForwarder

The inputs.conf and outputs.conf files that I need to update are not in these sub-directories. They are in C:\Program Files\SplunkUniversalForwarder\etc\system\local.

My question is, what "deployment-apps" sub-directory do I need to create and configure to make sure I'm updating the correct inputs.conf and outputs.conf files on my forwarder?

Thanks to all in advance.

0 Karma
1 Solution

OldManEd
Builder

This question is no longer valid. It was superseded by "Splunk Linux Deployment Server and the Windows Universal Forwarder Configuration Question". Sorry for the confusion. I can't figure out how to delete it.

View solution in original post

0 Karma

OldManEd
Builder

This question is no longer valid. It was superseded by "Splunk Linux Deployment Server and the Windows Universal Forwarder Configuration Question". Sorry for the confusion. I can't figure out how to delete it.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...