Getting Data In

Where are configuration details stored during the Universal Forwarder installation?

danielrichards
Explorer

Hi,

Selecting Windows IIS logs (C:\inetpub\logs\LogFiles\W3SVC) as event source during the installation of Universal Forwarder (splunkforwarder-6.5.1-f74036626f0c-x64-release.msi) resulted in data/events being forwarded to the Index (as expected), but I cannot find any entries in (C:\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf) to show for this selection I made during the installation.

Where are the config details stored when specifying during the UF Installation?

TIA
Danny

0 Karma
1 Solution

renjith_nair
SplunkTrust
SplunkTrust

Check in C:\Program Files\SplunkUniversalForwarder\etc\apps\search\local\inputs.conf
Easiest method is to use btool .. refer to https://docs.splunk.com/Documentation/Splunk/6.5.1/Troubleshooting/Usebtooltotroubleshootconfigurati...

Happy Splunking!

View solution in original post

0 Karma

sjohnson_splunk
Splunk Employee
Splunk Employee

As mentioned above, btool is your best bet for finding where a setting originates. Be sure to add the debug option so you can find the path:

splunk btool inputs list --debug > somefilename.txt

0 Karma

renjith_nair
SplunkTrust
SplunkTrust

Check in C:\Program Files\SplunkUniversalForwarder\etc\apps\search\local\inputs.conf
Easiest method is to use btool .. refer to https://docs.splunk.com/Documentation/Splunk/6.5.1/Troubleshooting/Usebtooltotroubleshootconfigurati...

Happy Splunking!
0 Karma

danielrichards
Explorer

You rock, many thanks

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...