Getting Data In

new to splunk - need help with input.conf

rsingh
Explorer

i am new to splunk that is already setup on our servers, my manager asked if i can edit the input.conf file so we can start deploying to workstations. where is the correct location i need to edit the file? also what option i can edit.

Thanks

Tags (1)
0 Karma
1 Solution

somesoni2
Revered Legend

It depends upon your Splunk Architecture/topology

1) If you've single standalone Splunk server performing every role, including that of a Forwarder (data monitoring), you'd find your inputs.conf on $SPLUNK_HOME/etc/system/local/ OR $SPLUNK_HOME/etc/apps/<>/local/ (preferred method for portability). Restart Splunk after making any changes.

2) If you've distributed Splunk environment and setup a deployment servers to deploy configurations to your forwarders, then

a) On Deployment server, you'll find inputs.con on $SPLUNK_HOME/etc/deployment-apps/<>/local/. IF you make changes to it, either reload deployment server OR restart it. More info here http://docs.splunk.com/Documentation/Splunk/6.4.3/Updating/Deploymentserverarchitecture

b) On Forwarders, it will in $SPLUNK_HOME/etc/apps/<>/local/. Ideally, the deployment server (serverclass.conf) should be configured in a way to restart the Forwarder automatically when a new content is received.

3) If you've forwarders not being managed by Deployment server, the you'd find your inputs.conf on $SPLUNK_HOME/etc/system/local/ OR $SPLUNK_HOME/etc/apps/<>/local/ on the Forwarder. Restart Splunk after making any changes.

View solution in original post

rsingh
Explorer

we have a single Splunk Server and i installed Splunk Forwarder on a workstation to test the input files. how can i point the input file to the workstation, do i even need to do that?

0 Karma

somesoni2
Revered Legend

It depends upon your Splunk Architecture/topology

1) If you've single standalone Splunk server performing every role, including that of a Forwarder (data monitoring), you'd find your inputs.conf on $SPLUNK_HOME/etc/system/local/ OR $SPLUNK_HOME/etc/apps/<>/local/ (preferred method for portability). Restart Splunk after making any changes.

2) If you've distributed Splunk environment and setup a deployment servers to deploy configurations to your forwarders, then

a) On Deployment server, you'll find inputs.con on $SPLUNK_HOME/etc/deployment-apps/<>/local/. IF you make changes to it, either reload deployment server OR restart it. More info here http://docs.splunk.com/Documentation/Splunk/6.4.3/Updating/Deploymentserverarchitecture

b) On Forwarders, it will in $SPLUNK_HOME/etc/apps/<>/local/. Ideally, the deployment server (serverclass.conf) should be configured in a way to restart the Forwarder automatically when a new content is received.

3) If you've forwarders not being managed by Deployment server, the you'd find your inputs.conf on $SPLUNK_HOME/etc/system/local/ OR $SPLUNK_HOME/etc/apps/<>/local/ on the Forwarder. Restart Splunk after making any changes.

inventsekar
SplunkTrust
SplunkTrust

There is an inputs.conf in $SPLUNK_HOME/etc/system/default/. To set custom
configurations, place an inputs.conf in $SPLUNK_HOME/etc/system/local/.

assuming /opt/splunk as your splunk home,

/opt/splunk/etc/system/local/inputs.conf is what your inputs.conf file.

You must restart Splunk to enable new configurations.
for full info about inputs.conf,
https://docs.splunk.com/Documentation/Splunk/6.4.2/Admin/Inputsconf

you may check this page for new data on boarding tasks..
http://docs.splunk.com/Documentation/Splunk/6.4.3/Data/Getstartedwithgettingdatain

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

gcusello
SplunkTrust
SplunkTrust

I suggest to you to follow one of the Tutorial starting from
http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial

Bye.
Giuseppe

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...