hi guy's.
recently added some windows hosts to our environment and they are forwarding data fine to our system. i want to add additional directories to monitor on the windows hosts but can't find the relevant config file to amend?
Hi attraqt,
you're looking for inputs.conf
read the docs http://docs.splunk.com/Documentation/Splunk/6.2.0/admin/Inputsconf about the monitor stanza ... asking what a stanza is? read the docs as well http://docs.splunk.com/Splexicon:Stanza 🙂
cheers, MuS
Hi attraqt,
you're looking for inputs.conf
read the docs http://docs.splunk.com/Documentation/Splunk/6.2.0/admin/Inputsconf about the monitor stanza ... asking what a stanza is? read the docs as well http://docs.splunk.com/Splexicon:Stanza 🙂
cheers, MuS
Ok cool. Looks like i found the correct path:
C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\local
Thanks for the docs Mus.
Having a look at the inputs.conf fiels listed and i can't see any of the configurations i made during the forwarder msi install. I've checked the local and defaults inputs.conf?
check as well in $SPLUNK_HOME/etc/apps
for any inputs.conf
where $SPLUNK_HOME
is the path where you installed the Splunk UF.