Getting Data In

Which configuration file do I make changes to on Windows hosts to add additional directories to monitor and where is this located?

attraqt
Explorer

hi guy's.

recently added some windows hosts to our environment and they are forwarding data fine to our system. i want to add additional directories to monitor on the windows hosts but can't find the relevant config file to amend?

0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi attraqt,

you're looking for inputs.conf read the docs http://docs.splunk.com/Documentation/Splunk/6.2.0/admin/Inputsconf about the monitor stanza ... asking what a stanza is? read the docs as well http://docs.splunk.com/Splexicon:Stanza 🙂

cheers, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi attraqt,

you're looking for inputs.conf read the docs http://docs.splunk.com/Documentation/Splunk/6.2.0/admin/Inputsconf about the monitor stanza ... asking what a stanza is? read the docs as well http://docs.splunk.com/Splexicon:Stanza 🙂

cheers, MuS

attraqt
Explorer

Ok cool. Looks like i found the correct path:

C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\local

attraqt
Explorer

Thanks for the docs Mus.

Having a look at the inputs.conf fiels listed and i can't see any of the configurations i made during the forwarder msi install. I've checked the local and defaults inputs.conf?

0 Karma

MuS
SplunkTrust
SplunkTrust

check as well in $SPLUNK_HOME/etc/apps for any inputs.conf where $SPLUNK_HOME is the path where you installed the Splunk UF.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...