Getting Data In

Where is data input configuration information entered from Splunk Web stored?

insidious
New Member

When I create a new data input (TCP port), where are these settings stored? I would have assumed it would be inputs.conf, but it is not located there.

Tags (1)
0 Karma

jkat54
SplunkTrust
SplunkTrust

Usually in the local directory of the app you were in when you created the input.

Example:
/opt/splunk/etc/apps/search/local/inputs.conf

Or maybe system local

/opt/splunk/etc/system/local/inputs.conf

Another tip is using btool to find where it is:

/opt/splunk/bin/splunk btool inputs list --debug

ChrisG
Splunk Employee
Splunk Employee

It should be (see Get data from TCP and UDP ports in the Getting Data In manual).

Are you looking at the right inputs.conf file? See Configuration file directories in the Admin Manual if you aren't familiar with the multiple versions of configuration files and where they sit in your installation.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...