Getting Data In

Where is data input configuration information entered from Splunk Web stored?

insidious
New Member

When I create a new data input (TCP port), where are these settings stored? I would have assumed it would be inputs.conf, but it is not located there.

Tags (1)
0 Karma

jkat54
SplunkTrust
SplunkTrust

Usually in the local directory of the app you were in when you created the input.

Example:
/opt/splunk/etc/apps/search/local/inputs.conf

Or maybe system local

/opt/splunk/etc/system/local/inputs.conf

Another tip is using btool to find where it is:

/opt/splunk/bin/splunk btool inputs list --debug

ChrisG
Splunk Employee
Splunk Employee

It should be (see Get data from TCP and UDP ports in the Getting Data In manual).

Are you looking at the right inputs.conf file? See Configuration file directories in the Admin Manual if you aren't familiar with the multiple versions of configuration files and where they sit in your installation.

0 Karma
Get Updates on the Splunk Community!

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...