Getting Data In

Which configuration file do I make changes to on Windows hosts to add additional directories to monitor and where is this located?

attraqt
Explorer

hi guy's.

recently added some windows hosts to our environment and they are forwarding data fine to our system. i want to add additional directories to monitor on the windows hosts but can't find the relevant config file to amend?

0 Karma
1 Solution

MuS
Legend

Hi attraqt,

you're looking for inputs.conf read the docs http://docs.splunk.com/Documentation/Splunk/6.2.0/admin/Inputsconf about the monitor stanza ... asking what a stanza is? read the docs as well http://docs.splunk.com/Splexicon:Stanza 🙂

cheers, MuS

View solution in original post

MuS
Legend

Hi attraqt,

you're looking for inputs.conf read the docs http://docs.splunk.com/Documentation/Splunk/6.2.0/admin/Inputsconf about the monitor stanza ... asking what a stanza is? read the docs as well http://docs.splunk.com/Splexicon:Stanza 🙂

cheers, MuS

attraqt
Explorer

Ok cool. Looks like i found the correct path:

C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\local

attraqt
Explorer

Thanks for the docs Mus.

Having a look at the inputs.conf fiels listed and i can't see any of the configurations i made during the forwarder msi install. I've checked the local and defaults inputs.conf?

0 Karma

MuS
Legend

check as well in $SPLUNK_HOME/etc/apps for any inputs.conf where $SPLUNK_HOME is the path where you installed the Splunk UF.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...