Getting Data In

Splunk - Adding stanza in input.conf file

rajiv_r
Explorer

i am using Splunk enterprise trial version and trying to push the windows logs to Splunk from the customize location . I gave the path location of my file which i want to push in /etc/system/local folder inside input.conf file and restarted the splunk server but still i could not able to see the file in splunk.
I have followed the below documents to add the stanza in the input.conf file
https://docs.splunk.com/Documentation/Splunk/8.0.1/Data/Monitorfilesanddirectorieswithinputs.conf

Can anyone please guide me in this as how to push the file ti splunk from a customize location
Note- I made the changes in the input.conf file inside splunk universal forwarder directory as i dont have $splunk_home file directory

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please post the inputs.conf settings for the logs and the search you are using to try to find the data.

Every Splunk instance has a $SPLUNK_HOME directory. It's the file system location where Splunk is installed. On Windows systems with a UF installed, it's often C:\Program Files\SplunkUniversalForwarder. $SPLUNK_HOME is Linux notation for a shell variable.

---
If this reply helps you, Karma would be appreciated.

rajiv_r
Explorer

again a lot of thanks for your answer i got it fixed..Actually document was saying to restart the server but actually we need to restart the forwarder only. And when i did it it started working

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please submit feedback (not a comment) on the documentation so Splunk can clarify what should be restarted.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...