Getting Data In

Where to make configuration changes in inputs.conf and outputs.conf on Linux?

ravisplunksap
New Member

Hi Team,

I have installed Splunk setup on one of my VM. On another VM I installed the Splunk universal forwarder to send the logs to Splunk Server.

I copied to make changes for inputs.conf and outputs.conf files to local folder to make changes because on default folder we shouldn't do changes.

So, they were so many attributes to make changes in both files. I am in confusion state.

Please tell me the basic values like where to insert host , source, sourcetype names, monitor file names, index name, etc in inputs.conf and where to give Splunk Server or Indexer IP, port number in outputs.conf.

Because i am setting up my test environment so that I wont do mistakes in my production environment .

Thanks & Regards,
Ravi

0 Karma
1 Solution

somesoni2
Revered Legend
0 Karma

ravisplunksap
New Member

thanks somesoni2

0 Karma

Richfez
SplunkTrust
SplunkTrust

This looked like it helped you significantly with your problem. I have converted this to an answer, If you agree it was helpful, could you mark it as Accepted? If not, ask some more!

0 Karma

ddrillic
Ultra Champion

It's hard to say where to start. Maybe at List of configuration files

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...