I have 200 or so entered from the input manager, but only about 30 show in the inputs.conf. I have been cloning and editing most of them, but even one of the ones i keep cloning does not show up in the inputs file.
$SPLUNK_HOME/bin/splunk btool inputs list --debug |grep somestring
Will give you the the file location of the inputs.
Also you can install and use Splunk on Splunk (SOS) to see your Config files
So.. I found some of them were being placed into the search app folder in that inputs.conf... but not all of them.
Still unable to locate where the inputs are defined. There are around less than half showing in the inputs.conf, but all are functioning and show in the website monitoring dashboard. any tips would be appreciated.
Could you clarify a couple things so that I can better understand what is going on? First, how you are cloning them? Do you mean are cloning them in via the file-system or are you cloning them in UI?
Second, what you mean by it isn't showing up in the inputs file? Are you saying that they don't show up in the manager UI?
I am cloning by clicking the clone link in the manager. Then editing the url and name and saving. They show up and work just fine in the UI. However when I go to look at the inputs.conf in the app-website monitor folder on the server, it only shows around 30 of those working inputs. My question is - how can it be working and showing up if they are not being written to that file? They must be listed in another area, but I do not know why or where. I had wanted to do a find/replace within that file to remove part of the url path for the subdirectory. It worked fine, but since they aren't all listed there I can't fix the rest.