Getting Data In
Highlighted

## Where are configuration details stored during the Universal Forwarder installation?

New Member

Hi,

Selecting Windows IIS logs (C:\inetpub\logs\LogFiles\W3SVC) as event source during the installation of Universal Forwarder (splunkforwarder-6.5.1-f74036626f0c-x64-release.msi) resulted in data/events being forwarded to the Index (as expected), but I cannot find any entries in (C:\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf) to show for this selection I made during the installation.

Where are the config details stored when specifying during the UF Installation?

TIA
Danny

Tags (3)
1 Solution
Highlighted

## Re: Where are configuration details stored during the Universal Forwarder installation?

SplunkTrust

Check in C:\Program Files\SplunkUniversalForwarder\etc\apps\search\local\inputs.conf
Easiest method is to use btool .. refer to https://docs.splunk.com/Documentation/Splunk/6.5.1/Troubleshooting/Usebtooltotroubleshootconfigurati...

Highlighted

## Re: Where are configuration details stored during the Universal Forwarder installation?

New Member

You rock, many thanks

Highlighted

## Re: Where are configuration details stored during the Universal Forwarder installation?

Contributor

As mentioned above, btool is your best bet for finding where a setting originates. Be sure to add the debug option so you can find the path:

splunk btool inputs list --debug > somefilename.txt