Getting Data In

Where are configuration details stored during the Universal Forwarder installation?

danielrichards
Explorer

Hi,

Selecting Windows IIS logs (C:\inetpub\logs\LogFiles\W3SVC) as event source during the installation of Universal Forwarder (splunkforwarder-6.5.1-f74036626f0c-x64-release.msi) resulted in data/events being forwarded to the Index (as expected), but I cannot find any entries in (C:\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf) to show for this selection I made during the installation.

Where are the config details stored when specifying during the UF Installation?

TIA
Danny

0 Karma
1 Solution

renjith_nair
Legend

Check in C:\Program Files\SplunkUniversalForwarder\etc\apps\search\local\inputs.conf
Easiest method is to use btool .. refer to https://docs.splunk.com/Documentation/Splunk/6.5.1/Troubleshooting/Usebtooltotroubleshootconfigurati...

Happy Splunking!

View solution in original post

0 Karma

sjohnson_splunk
Splunk Employee
Splunk Employee

As mentioned above, btool is your best bet for finding where a setting originates. Be sure to add the debug option so you can find the path:

splunk btool inputs list --debug > somefilename.txt

0 Karma

renjith_nair
Legend

Check in C:\Program Files\SplunkUniversalForwarder\etc\apps\search\local\inputs.conf
Easiest method is to use btool .. refer to https://docs.splunk.com/Documentation/Splunk/6.5.1/Troubleshooting/Usebtooltotroubleshootconfigurati...

Happy Splunking!
0 Karma

danielrichards
Explorer

You rock, many thanks

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...