This file has been manually created on a universal forwarder:
/opt/splunkforwarder/etc/apps/my_TA/local/inputs.conf
[monitor:///var/log/messages]
sourcetype=syslog
index=syslog
A new Splunk admin comes in and connects the universal forwarders to a deployment server and deploys the same app with a new inputs.conf file:
/opt/splunk/etc/deployment-apps/my_TA/local/inputs.conf
[monitor:///var/log/maillog]
sourcetype=maillog
index=syslog
Which file is now monitored?
Stressplein
Highly Voted 4 years agoApis
Highly Voted 2 years, 5 months agobobixaka
Most Recent 7 months, 2 weeks agoInfoSec_RC53
1 year, 3 months agogibla1929
2 years agoZeusP
3 years agoTony_123
3 years, 4 months agopucca012
3 years, 4 months agoHamiltonian
2 years, 11 months agoHamiltonian
2 years, 11 months agosargeholik
3 years, 5 months agoSandy_1988
3 years, 6 months agosergito095
3 years, 11 months agoHamiltonian
2 years, 11 months agoAshton_98
3 years, 7 months agomker
4 years agomker
4 years ago