How, and what files specifically, do I configure to get data into Splunk enterprise from the localhost? I thought it would be as simple as modifying inputs.conf that I created (shown below), but that didn't change anything. Thoughts?
\Splunk\etc\apps\SplunkForwarder\local\inputs.conf
similar to the inputs.conf file on my system with Universal Forwarder:
'\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local\inputs.conf
Setup: Sys1: Windows 10, Splunk Enterprise Sys2: Windows 10, Universal Forwarder
Logs from Sys2 are in Splunk Enterprise, but I can't see anything from Sys1.
Thanks!
... View more