I've been working with Splunk for many years and have always made changes via the .conf files. However, I recently added the /var/logs directory by using
./splunk add monitor /var/log -index main -sourcetype linux
It's working, but I want to modify it a bit. However, I have been pulling my hair out trying to figure out which inputs.conf file was modified with the command.
Any assistance appreciated.
Tim
Hi @tsheets13 ,
You can btool command to check where your config lies for ex. ./splunk btool inputs list --debug
./splunk btool inputs list --debug
-----
If this reply helps an upvote will be appreciated
Hi @tsheets13 ,
You can btool command to check where your config lies for ex. ./splunk btool inputs list --debug
./splunk btool inputs list --debug
-----
If this reply helps an upvote will be appreciated