Getting Data In

Which configuration file do I make changes to on Windows hosts to add additional directories to monitor and where is this located?

attraqt
Explorer

hi guy's.

recently added some windows hosts to our environment and they are forwarding data fine to our system. i want to add additional directories to monitor on the windows hosts but can't find the relevant config file to amend?

0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi attraqt,

you're looking for inputs.conf read the docs http://docs.splunk.com/Documentation/Splunk/6.2.0/admin/Inputsconf about the monitor stanza ... asking what a stanza is? read the docs as well http://docs.splunk.com/Splexicon:Stanza 🙂

cheers, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi attraqt,

you're looking for inputs.conf read the docs http://docs.splunk.com/Documentation/Splunk/6.2.0/admin/Inputsconf about the monitor stanza ... asking what a stanza is? read the docs as well http://docs.splunk.com/Splexicon:Stanza 🙂

cheers, MuS

View solution in original post

attraqt
Explorer

Ok cool. Looks like i found the correct path:

C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\local

attraqt
Explorer

Thanks for the docs Mus.

Having a look at the inputs.conf fiels listed and i can't see any of the configurations i made during the forwarder msi install. I've checked the local and defaults inputs.conf?

0 Karma

MuS
SplunkTrust
SplunkTrust

check as well in $SPLUNK_HOME/etc/apps for any inputs.conf where $SPLUNK_HOME is the path where you installed the Splunk UF.

0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!