Getting Data In

Deployed Inputs.conf Doesn't Work but system/local does?

stevepraz
Path Finder

Looking for a little help after fooling around with this for awhile. I have several forwarders on Windows and a Windows deployment server. The forwarders are installed with a configuration to point to the deployment server and they are successfully pulling down an app with outputs.conf that points them to the right indexers. This is working as I see the splunkd logs for each one coming in.

Today I started working on an app to deploy an inputs.conf file to enable event log monitoring. Here is the contents of the file:

[WinEventLog://Application]
index=wineventlog
disabled=0

[WinEventLog://Security]
index=wineventlog
disabled=0

[WinEventLog://System]
index=wineventlog
disabled=0

The app gets deployed successfully and the forwarders restart themselves but no data comes in. I removed the app from one of the forwarders and put the same stanzas above into the system/local/inputs.conf and bounced and it started working ok.

I can't figure out why the deployed version would work. These forwarders are stock, with no other custom apps (besides the output.conf). I've read through the config precedence document and can't see any place that something else would be overriding the inputs.conf in the custom app.

Any ideas?

0 Karma
1 Solution

stevepraz
Path Finder

Sorry about that... realized my silly mistake. In the more recent app structure, I created "defaults" rather than "default". After I renamed, things seem to be working.

View solution in original post

0 Karma

stevepraz
Path Finder

Sorry about that... realized my silly mistake. In the more recent app structure, I created "defaults" rather than "default". After I renamed, things seem to be working.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...