Getting Data In

log file created in launcher and search folder

SplunkCSIT
Communicator

how come when i configured the data in the heavy forwarder, sometimes it will created in launcher folder /etc/apps/launcher/local/inputs.conf, sometime it created in search folder /etc/apps/search/local/inputs.conf. How to resolve those that already created in launcher and move to search folder?thks

Tags (2)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

You'll get inputs in the launcher app if you add it from within the launcher app. Functionally it doesn't matter where the input is defined, but for maintenance it's indeed a good idea to consolidate that in one app. For future inputs, make sure you first enter the search app and then add the input. For existing inputs, move the stanza from /etc/apps/launcher/local/inputs.conf to /etc/apps/search/local/inputs.conf and restart.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

You'll get inputs in the launcher app if you add it from within the launcher app. Functionally it doesn't matter where the input is defined, but for maintenance it's indeed a good idea to consolidate that in one app. For future inputs, make sure you first enter the search app and then add the input. For existing inputs, move the stanza from /etc/apps/launcher/local/inputs.conf to /etc/apps/search/local/inputs.conf and restart.

martin_mueller
SplunkTrust
SplunkTrust

Given a choice of those two, I'd pick the search app every time.

As soon as your deployment grows it'll make sense to group inputs into their own apps, and deploy those apps as a whole onto their forwarders.

0 Karma

SplunkCSIT
Communicator

thks, for best practice, we should put the indexes.conf and inputs.conf in launcher folder or search folder?

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...