This widget could not be displayed.
  • ">Apps & Add-ons
  • Getting Data In

    How do you btool inputs.conf?

    Mohsin123
    Path Finder

    hi,
    can you please tell me what is the right way to btool inputs.conf for a specific app context. I want to troubleshoot this error that is too much in my splunk search head messages notification : Received index from dleeted/missing/unconfigured indexes. I read previous blogs: it says your inputs.conf is sending data to an indx that doesnt exist

    0 Karma
    1 Solution

    sbbadri
    Motivator

    @shraddhamuduli

    Login to the UF which you have got that error message and execute below command,

    $SPLUNK_HOME$/bin/splunk btool inputs list --debug

    Then find the stanza.

    Below are the links which will be helpful to you,

    https://www.splunk.com/blog/2012/10/02/tips-and-tricks-for-the-new-guy.html
    https://docs.splunk.com/Documentation/Splunk/6.6.3/Troubleshooting/Usebtooltotroubleshootconfigurati...

    View solution in original post

    sbbadri
    Motivator

    @shraddhamuduli

    Login to the UF which you have got that error message and execute below command,

    $SPLUNK_HOME$/bin/splunk btool inputs list --debug

    Then find the stanza.

    Below are the links which will be helpful to you,

    https://www.splunk.com/blog/2012/10/02/tips-and-tricks-for-the-new-guy.html
    https://docs.splunk.com/Documentation/Splunk/6.6.3/Troubleshooting/Usebtooltotroubleshootconfigurati...

    Mohsin123
    Path Finder

    thanks . by uf , do u mean this path in our deployment server right ?
    /opt/splunk/etc/deployment-apps/

    0 Karma

    sbbadri
    Motivator

    I meant Universal Forwarder. /opt/splunk/splunkuniversalforwarder/bin

    0 Karma
    Get Updates on the Splunk Community!

    Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

    WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

    Industry Solutions for Supply Chain and OT, Amazon Use Cases, Plus More New Articles ...

    Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

    Enterprise Security Content Update (ESCU) | New Releases

    In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...