Hello, everyone. I just ran into an issue where a stanza within apps\SplunkUniversalForwarder\local\inputs.conf on a forwarder is overwriting other apps\AppName\local\inputs.conf from o...
Hello, I have made a new app under deployment apps with the following inputs.conf [monitor:///root/something/something/something/something/]
index = test
whitelist=console-202[\S\s...
hi,
can you please tell me what is the right way to btool inputs.conf for a specific app context. I want to troubleshoot this error that is too much in my splunk search head messages n...
Hello,
I have a odd issue which seems to have been resolved but I would like to know the root cause of this issue. I inherited a splunk configuration with one of the stanza entries in inputs.conf...
Having some trouble blacklisting a folder that has multiple dynamic subfolders and files. I want to blacklist everything for dir1 including files and any subfolders which are created dynamically. Spl...
...iles\somepath..... so created an inputs.conf as follows
[monitor://C:\Program Files\somepath\]
index=someindex
sourcetype=somesourcetype
whitelist=\logfile.*$
Restarted the Windows UF s...
Anyone know why 5.0.1 UFs are reporting data in with host name of $decideonstartup. Looks like this setting was added in 5.0 for the inputs.conf file and the default for system/default/inputs.conf....
Hi there, I want to be able to allow a dashboard of my app read the hostname stored in inputs.conf, which is provided by user when setting up the app. Specifically, I have a button on one of my a...
First time splunker here.
Can you have an inputs.conf with only:
[default]
host = <fqdn>
In etc/system/local while having custom apps with inputs in etc/apps? Or will the etc/system/l...