Getting Data In

Using "btool inpust list" monitor stanza is missing, but not when using "btool -app=xx inputs list"

rune_hellem
Contributor

Using command splunk btool --app=operations_inputs_prod inputs list the following is listed

[monitor://D:\logs\powershell\*.log]
index = klpoperations
sourcetype = log4net
whitelist = .*\.log

But if I try the command without the --app to list all configuraitons, the one above is missing, but not the three others in the file, and I'm not able to figure out why. I have tried a lot of different things, reloading the deploy-server a lot of times.

splunk btool inputs list
0 Karma

koshyk
Super Champion

Best thing is to do is to use debug , so you know exactly which APP the stanza is coming from. Then you can do app specific btool

splunk cmd btool inputs list debug > /tmp/inputs.btool.txt

you should see each line, which app it belongs to..

0 Karma

rune_hellem
Contributor

Well, it provides all details about the stanzas that the forwarder is configured to use, but still it won't explain why the one stanza is not part of the output, but the three others are.

It is worth mentioning that there are other inputs.conf for other indexes on the same server which are identical and are to be found in the config. So it should not be anything wrong with the missing stanza, they are identical.

0 Karma

ddrillic
Ultra Champion

On which server are you running the btool command, the forwarder or the deployment server?

0 Karma

rune_hellem
Contributor

On the forwarder...

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...