Getting Data In

Where is data input configuration information entered from Splunk Web stored?

insidious
New Member

When I create a new data input (TCP port), where are these settings stored? I would have assumed it would be inputs.conf, but it is not located there.

Tags (1)
0 Karma

jkat54
SplunkTrust
SplunkTrust

Usually in the local directory of the app you were in when you created the input.

Example:
/opt/splunk/etc/apps/search/local/inputs.conf

Or maybe system local

/opt/splunk/etc/system/local/inputs.conf

Another tip is using btool to find where it is:

/opt/splunk/bin/splunk btool inputs list --debug

ChrisG
Splunk Employee
Splunk Employee

It should be (see Get data from TCP and UDP ports in the Getting Data In manual).

Are you looking at the right inputs.conf file? See Configuration file directories in the Admin Manual if you aren't familiar with the multiple versions of configuration files and where they sit in your installation.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...