Getting Data In

What deployment apps subdirectory on a Linux Deployment Server do I need to update inputs.conf and outputs.conf on a Windows Universal Forwarder?

OldManEd
Builder

I'm trying to follow the Splunk documentation to set up my Splunk Linux Deployment Server to update configuration files for my Windows servers using the Splunk Forwarder. Specifically, I would like to update the C:\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf and outputs.conf files automatically when needed from the Linux deployment server. Looking at the documentation example, it appears that they are asking to create the following directory on the deployment server to accomplish this; $SPLUNK_HOME/etc/deployment-apps/<deployment app name>/default/inputs.conf.

My question is, is this correct? I thought changing any files in any app under the "default" sub-directory was an incorrect procedure. Also, on the Windows forwarder, the listing under the C:\Program Files\SplunkUniversalForwarder\etc\apps\ is;

introspection_generator_addon
learned
search
splunk_httpinput
Splunk_TA_windows
SplunkUniversalForwarder

The inputs.conf and outputs.conf files that I need to update are not in these sub-directories. They are in C:\Program Files\SplunkUniversalForwarder\etc\system\local.

My question is, what "deployment-apps" sub-directory do I need to create and configure to make sure I'm updating the correct inputs.conf and outputs.conf files on my forwarder?

Thanks to all in advance.

0 Karma
1 Solution

OldManEd
Builder

This question is no longer valid. It was superseded by "Splunk Linux Deployment Server and the Windows Universal Forwarder Configuration Question". Sorry for the confusion. I can't figure out how to delete it.

View solution in original post

0 Karma

OldManEd
Builder

This question is no longer valid. It was superseded by "Splunk Linux Deployment Server and the Windows Universal Forwarder Configuration Question". Sorry for the confusion. I can't figure out how to delete it.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...