Getting Data In

log file created in launcher and search folder

SplunkCSIT
Communicator

how come when i configured the data in the heavy forwarder, sometimes it will created in launcher folder /etc/apps/launcher/local/inputs.conf, sometime it created in search folder /etc/apps/search/local/inputs.conf. How to resolve those that already created in launcher and move to search folder?thks

Tags (2)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

You'll get inputs in the launcher app if you add it from within the launcher app. Functionally it doesn't matter where the input is defined, but for maintenance it's indeed a good idea to consolidate that in one app. For future inputs, make sure you first enter the search app and then add the input. For existing inputs, move the stanza from /etc/apps/launcher/local/inputs.conf to /etc/apps/search/local/inputs.conf and restart.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

You'll get inputs in the launcher app if you add it from within the launcher app. Functionally it doesn't matter where the input is defined, but for maintenance it's indeed a good idea to consolidate that in one app. For future inputs, make sure you first enter the search app and then add the input. For existing inputs, move the stanza from /etc/apps/launcher/local/inputs.conf to /etc/apps/search/local/inputs.conf and restart.

martin_mueller
SplunkTrust
SplunkTrust

Given a choice of those two, I'd pick the search app every time.

As soon as your deployment grows it'll make sense to group inputs into their own apps, and deploy those apps as a whole onto their forwarders.

0 Karma

SplunkCSIT
Communicator

thks, for best practice, we should put the indexes.conf and inputs.conf in launcher folder or search folder?

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...