Splunk Dev

Where is my monitor stanza?


I have added monitoring with below command on my windows client.

./splunk add monitor C:\path\to.log -index qa -sourcetype pcs_log -host <ip>

I can see above path in monitored file list when I execute splunk list monitor.

As per my understanding splunk add monitor adds below stanza in inputs.conf. Isn't it? But I am unable to find these lines in any of inputs.conf file. I have checked /etc/system/local/inputs.conf but it doesnt have these values.

disabled = 0
setting1 = value
setting2 = value

I am using splunk cloud and installed universal forwarder. can you please help?

Tags (1)
0 Karma

Splunk Employee
Splunk Employee

When you add a monitor from the CLI it goes to the search app, local, inputs config. $SPLUNK_HOME\etc\apps\search\local\inputs.conf

0 Karma



The inputs.conf could be created under your app also. Easy way to find is using btool

./splunk cmd btool inputs list --debug | grep 'your known string'
Happy Splunking!
0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out &gt;&gt; As our brave ...