I need to setup a TCP data input and I need to ensure that it is SSL/TLS.
I understand that I can add a stanza to an inputs.conf file as referenced in this post:
https://answers.splunk.com/answers/684045/how-to-enable-tcp-data-input-with-ssl.html?utm_source=type...
My question is - which inputs.conf file? The data is coming in to my Search Head server and there are a bunch of apps installed there, each with their own inputs.conf file. Which one controls the TCP Data Inputs?
Thanks.
Any app can contain inputs.conf and set TCP attributes. I recommend creating a custom app (org_tcpinputs) for the settings. Before restarting Splunk to apply the changes, run btool to verify the settings are as you expect. That's to avoid conflicts with another app.
Is there a default place where the TCP Input would look for its settings once I have created it?
Splunk looks in all inputs.conf files and merges what it finds based on the precedence order described at https://docs.splunk.com/Documentation/Splunk/8.0.2/Admin/Wheretofindtheconfigurationfiles