Getting Data In

Where are configuration details stored during the Universal Forwarder installation?

danielrichards
Explorer

Hi,

Selecting Windows IIS logs (C:\inetpub\logs\LogFiles\W3SVC) as event source during the installation of Universal Forwarder (splunkforwarder-6.5.1-f74036626f0c-x64-release.msi) resulted in data/events being forwarded to the Index (as expected), but I cannot find any entries in (C:\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf) to show for this selection I made during the installation.

Where are the config details stored when specifying during the UF Installation?

TIA
Danny

0 Karma
1 Solution

renjith_nair
Legend

Check in C:\Program Files\SplunkUniversalForwarder\etc\apps\search\local\inputs.conf
Easiest method is to use btool .. refer to https://docs.splunk.com/Documentation/Splunk/6.5.1/Troubleshooting/Usebtooltotroubleshootconfigurati...

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

0 Karma

sjohnson_splunk
Splunk Employee
Splunk Employee

As mentioned above, btool is your best bet for finding where a setting originates. Be sure to add the debug option so you can find the path:

splunk btool inputs list --debug > somefilename.txt

0 Karma

renjith_nair
Legend

Check in C:\Program Files\SplunkUniversalForwarder\etc\apps\search\local\inputs.conf
Easiest method is to use btool .. refer to https://docs.splunk.com/Documentation/Splunk/6.5.1/Troubleshooting/Usebtooltotroubleshootconfigurati...

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

danielrichards
Explorer

You rock, many thanks

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Enhance Security Operations with Automated Threat Analysis in the Splunk EcosystemAre you leveraging ...

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...