Getting Data In

Where is data input configuration information entered from Splunk Web stored?

insidious
New Member

When I create a new data input (TCP port), where are these settings stored? I would have assumed it would be inputs.conf, but it is not located there.

Tags (1)
0 Karma

jkat54
SplunkTrust
SplunkTrust

Usually in the local directory of the app you were in when you created the input.

Example:
/opt/splunk/etc/apps/search/local/inputs.conf

Or maybe system local

/opt/splunk/etc/system/local/inputs.conf

Another tip is using btool to find where it is:

/opt/splunk/bin/splunk btool inputs list --debug

ChrisG
Splunk Employee
Splunk Employee

It should be (see Get data from TCP and UDP ports in the Getting Data In manual).

Are you looking at the right inputs.conf file? See Configuration file directories in the Admin Manual if you aren't familiar with the multiple versions of configuration files and where they sit in your installation.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...