Getting Data In

Where is data input configuration information entered from Splunk Web stored?

insidious
New Member

When I create a new data input (TCP port), where are these settings stored? I would have assumed it would be inputs.conf, but it is not located there.

Tags (1)
0 Karma

jkat54
SplunkTrust
SplunkTrust

Usually in the local directory of the app you were in when you created the input.

Example:
/opt/splunk/etc/apps/search/local/inputs.conf

Or maybe system local

/opt/splunk/etc/system/local/inputs.conf

Another tip is using btool to find where it is:

/opt/splunk/bin/splunk btool inputs list --debug

ChrisG
Splunk Employee
Splunk Employee

It should be (see Get data from TCP and UDP ports in the Getting Data In manual).

Are you looking at the right inputs.conf file? See Configuration file directories in the Admin Manual if you aren't familiar with the multiple versions of configuration files and where they sit in your installation.

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...