Getting Data In

Manual Inputs, what location are they kept?

_z_
Explorer

Not new to Splunk, but new to 4.2.2.
I had setup a forwarder and manually entered specific paths to monitor:

/p01/foo/bar/logs/server.log
/p02/foo/bar/logs/server.log
went to on to p50.

I just wanted to get Splunk 'working'.
I looked in the local/inputs.conf but the information was not there. So where is it kept?

I have to ask because I removed the above, edited ../local/inputs.conf and added:

[monitor:/p*/foo/bar/logs]
index = default
ignoreOlderThan = 3d

As I wanted to index all the logs within the 'logs' dir.

Now it appears the forwarder is not sending OR the indexer is no longer indexing. I am guessing the original configuration is kept someplace and messing up my ../local/inputs.conf

Any ideas?

1 Solution

_z_
Explorer
$ find . -name inputs.conf -print
./splunk/etc/system/default/inputs.conf
./splunk/etc/system/local/inputs.conf
./splunk/etc/apps/launcher/local/inputs.conf
./splunk/etc/apps/SplunkLightForwarder/default/inputs.conf
./splunk/etc/apps/SplunkDeploymentMonitor/local/inputs.conf
./splunk/etc/apps/sample_app/default/inputs.conf
./splunk/etc/apps/unix/default/inputs.conf
./splunk/etc/apps/unix/local/inputs.conf
./splunk/etc/modules/distributedDeployment/classes/deployable/inputs.conf

The file I was looking for is in ../launcher/local/inputs.conf

I still have an issue with the indexing not working, but since this was my original question, I will mark it answered.

View solution in original post

_z_
Explorer
$ find . -name inputs.conf -print
./splunk/etc/system/default/inputs.conf
./splunk/etc/system/local/inputs.conf
./splunk/etc/apps/launcher/local/inputs.conf
./splunk/etc/apps/SplunkLightForwarder/default/inputs.conf
./splunk/etc/apps/SplunkDeploymentMonitor/local/inputs.conf
./splunk/etc/apps/sample_app/default/inputs.conf
./splunk/etc/apps/unix/default/inputs.conf
./splunk/etc/apps/unix/local/inputs.conf
./splunk/etc/modules/distributedDeployment/classes/deployable/inputs.conf

The file I was looking for is in ../launcher/local/inputs.conf

I still have an issue with the indexing not working, but since this was my original question, I will mark it answered.

kristian_kolb
Ultra Champion

Hm, and the monitor command takes a few more slashes (assuming that this is your actual conf)

Suggest you try

[monitor://]

and remember that the path might start with an additional slash...

Hope this helps.

/Kristian

0 Karma

_z_
Explorer

Kristian,

Yep, I tried the '///' in front as well.. no joy.

Thanks!

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi z

how did you entered the paths to monitor? if it was over the 'webUI / Manager' it will propably end up in etc/apps/search/local.

and keep reading

regards

_z_
Explorer

MuS, just wanted to followup. I have another forwarder which I also setup manually via the Manager UI ... The etc/app/search/local dir does not exist...

So still looking for where these are kept.

0 Karma

_z_
Explorer

MuS,
I checked the path... the inputs.conf there is empty, which is correct since I removed all the entries I made.

I had reviewed that document you provided before... maybe I have to re-re-read...

0 Karma

_z_
Explorer

Yes, the original inputs were via the webUI/Manager...

I will check out the path, thanks!

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...