Getting Data In

What deployment apps subdirectory on a Linux Deployment Server do I need to update inputs.conf and outputs.conf on a Windows Universal Forwarder?

OldManEd
Builder

I'm trying to follow the Splunk documentation to set up my Splunk Linux Deployment Server to update configuration files for my Windows servers using the Splunk Forwarder. Specifically, I would like to update the C:\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf and outputs.conf files automatically when needed from the Linux deployment server. Looking at the documentation example, it appears that they are asking to create the following directory on the deployment server to accomplish this; $SPLUNK_HOME/etc/deployment-apps/<deployment app name>/default/inputs.conf.

My question is, is this correct? I thought changing any files in any app under the "default" sub-directory was an incorrect procedure. Also, on the Windows forwarder, the listing under the C:\Program Files\SplunkUniversalForwarder\etc\apps\ is;

introspection_generator_addon
learned
search
splunk_httpinput
Splunk_TA_windows
SplunkUniversalForwarder

The inputs.conf and outputs.conf files that I need to update are not in these sub-directories. They are in C:\Program Files\SplunkUniversalForwarder\etc\system\local.

My question is, what "deployment-apps" sub-directory do I need to create and configure to make sure I'm updating the correct inputs.conf and outputs.conf files on my forwarder?

Thanks to all in advance.

0 Karma
1 Solution

OldManEd
Builder

This question is no longer valid. It was superseded by "Splunk Linux Deployment Server and the Windows Universal Forwarder Configuration Question". Sorry for the confusion. I can't figure out how to delete it.

View solution in original post

0 Karma

OldManEd
Builder

This question is no longer valid. It was superseded by "Splunk Linux Deployment Server and the Windows Universal Forwarder Configuration Question". Sorry for the confusion. I can't figure out how to delete it.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...