recently added some windows hosts to our environment and they are forwarding data fine to our system. i want to add additional directories to monitor on the windows hosts but can't find the relevant config file to amend?
you're looking for
inputs.conf read the docs http://docs.splunk.com/Documentation/Splunk/6.2.0/admin/Inputsconf about the monitor stanza ... asking what a stanza is? read the docs as well http://docs.splunk.com/Splexicon:Stanza 🙂
Thanks for the docs Mus.
Having a look at the inputs.conf fiels listed and i can't see any of the configurations i made during the forwarder msi install. I've checked the local and defaults inputs.conf?
check as well in
$SPLUNK_HOME/etc/apps for any
$SPLUNK_HOME is the path where you installed the Splunk UF.
Ok cool. Looks like i found the correct path: