Getting Data In

Windows Universal Forwarder - initial configuration settings dont seem to be in *.conf

bbegyperkspot
Explorer

When installing a UF on Windows, the installer prompts for sources to forward, including event logs or a path.

I put in a path to some IIS logs but have come to regret my decision. I want to change the values, but I can't find them.

They aren't in

C:\Program Files\SplunkUniversalForwarder\etc\system\local\outputs.conf

or

C:\Program Files\SplunkUniversalForwarder\etc\system\default\outputs.conf

Where are the settings captured during the install and how can I change them?

0 Karma

bbegyperkspot
Explorer

Ok, found it under SplunkTAwindows. So which is the preferred location to declare directories I want monitored?

0 Karma

somesoni2
Revered Legend

The conf file to look for will be inputs.conf. Search inputs.conf in following locations

C:\Program Files\SplunkUniversalForwarder\etc\system\local
C:\Program Files\SplunkUniversalForwarder\etc\system\default
C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\local

Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...