Getting Data In

location of configuration for inputs set up with installer windows based forwarder

dominiquevocat
Motivator

We have set up universal forwarders on Windows. During the setup one can specify to monitor a specific folder and not much more.

The folder and files under it are listed by running
splunk list monitor
however i would like to specify the target index, sourcetype and also perform some regex on the filename to set some properties.

I have had a look at every inputs.conf on the machine and fail to see the "[monitor:" stanza that tails this path.

Tags (2)
0 Karma
1 Solution

dominiquevocat
Motivator

I did overlook $SPLUNK_HOME\etc\apps\MSICreated\inputs.conf as per aholzer ( http://answers.splunk.com/users/142151/aholzer )

View solution in original post

0 Karma

dominiquevocat
Motivator

I did overlook $SPLUNK_HOME\etc\apps\MSICreated\inputs.conf as per aholzer ( http://answers.splunk.com/users/142151/aholzer )

0 Karma

dominiquevocat
Motivator

indeed, it was in the (somehow overlooked) \MSICreated 😕 thanks!

0 Karma

jtrucks
Splunk Employee
Splunk Employee

Install the Splunk on Splunk app and go to Data Inputs -> File Monitor Inputs to see where this is likely configured and how it is set up. Also, search the entire Splunk Forwarder for any file named inputs.conf and then be sure to look in every one of those files. It might not be written into the file in the exact way you expect, so you may have to search for a subset of our file path, say just one directory in the path, to find it - or just look manually as there aren't that many places to look.

--
Jesse Trucks
Minister of Magic

dominiquevocat
Motivator

thanks for the heads up, i will have to check what firewall rules are needed in order to see the forwarder - i only see the main indexer in S.o.S. etc. but thanks.

0 Karma

aholzer
Motivator

I find it highly unlikely that you searched ALL inputs.conf on the host. If these events are being generated from that host, then an inputs.conf must exist, the only question is where

If you set up the monitoring via the .msi it's probably under $SPLUNK_HOME\etc\apps\MSICreated\ either in local or default. On the bright side you can simply create an inputs.conf inside of $SPLUNK_HOME\etc\system\local and override the inputs.conf without having to find it. I wouldn't suggest this, because you now have to maintain this file rather than a file inside an app. You can do this as a last resort

Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...