Getting Data In

What deployment apps subdirectory on a Linux Deployment Server do I need to update inputs.conf and outputs.conf on a Windows Universal Forwarder?

OldManEd
Builder

I'm trying to follow the Splunk documentation to set up my Splunk Linux Deployment Server to update configuration files for my Windows servers using the Splunk Forwarder. Specifically, I would like to update the C:\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf and outputs.conf files automatically when needed from the Linux deployment server. Looking at the documentation example, it appears that they are asking to create the following directory on the deployment server to accomplish this; $SPLUNK_HOME/etc/deployment-apps/<deployment app name>/default/inputs.conf.

My question is, is this correct? I thought changing any files in any app under the "default" sub-directory was an incorrect procedure. Also, on the Windows forwarder, the listing under the C:\Program Files\SplunkUniversalForwarder\etc\apps\ is;

introspection_generator_addon
learned
search
splunk_httpinput
Splunk_TA_windows
SplunkUniversalForwarder

The inputs.conf and outputs.conf files that I need to update are not in these sub-directories. They are in C:\Program Files\SplunkUniversalForwarder\etc\system\local.

My question is, what "deployment-apps" sub-directory do I need to create and configure to make sure I'm updating the correct inputs.conf and outputs.conf files on my forwarder?

Thanks to all in advance.

0 Karma
1 Solution

OldManEd
Builder

This question is no longer valid. It was superseded by "Splunk Linux Deployment Server and the Windows Universal Forwarder Configuration Question". Sorry for the confusion. I can't figure out how to delete it.

View solution in original post

0 Karma

OldManEd
Builder

This question is no longer valid. It was superseded by "Splunk Linux Deployment Server and the Windows Universal Forwarder Configuration Question". Sorry for the confusion. I can't figure out how to delete it.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...