Splunk Dev

ModularInput - Input not written in myapp/local/inputs.conf but in /search/local/inputs.conf

rechteklebe
Path Finder

Hi, 

I've recognized that my modularinput configuration for "myapp" has a strange situation.

When I am in Splunk using "myapp" and go to Data Inputs>MyAppInput, the inputs.conf file gets written properly (<myapp>/local/inputs.conf).

But when someone is in another app than "myapp" (e.g. search), and goes to Data Inputs>MyAppInput, the data gets written to /search/local/inputs.conf (not "myapp" app).

It gets written to the application folder from where you click on "Data Inputs".

How can i make sure that from wherever the user clicks on " Data Inputs>MyAppInput", the data gets only written in  (<myapp>/local/inputs.conf)?

Thanks!

Labels (1)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

That’s Splunk Enterprise default behavior.

otherwise splunk doesn’t know where to write custom configurations. 

————————————
If this helps, give a like below.
0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...