I was installing the Linux AuditD app and the TA on my Splunk instance and my forwarders installed on RHEL 7 systems when I noticed that there's no inputs.conf file in either the app or the TA. How are my indexers supposed to get and use any data from the systems without the forwarders sending the data over? Am I just supposed to make one myself?
I had a look at the video guide for version v2 (something like 6 years ago), and that one seems to have an inputs.conf file, unlike the current version v3.
... View more