Quick question, I'm still getting my feet wet with Splunk but I was wondering how long does it typically take to receive data after installing a universal forwarder? Does it depend on the how much or type of data?
I'm trying to setup a test environment for testing the Splunk for AD app. I have a Win 2008 R2 Box setup as a domain controller forwarding to a Splunk 5.0 instance on linux. I'm testing what happens when I modify the inputs.conf file. From what I'm seeing after I modify the inputs.conf file and restart the service it can take hours before any data is received. Is that normal? I've tried adjusting the input.conf files so I only get the new data but nothing seems to happen.
I have done a default install of the Splunk for AD app in my Windows system. Installed the universal forwarder without selecting any inputs. After it was installed I stopped the service and copied the Windows, DNS and Domain Controller TA to the apps folder. Below is a sample output from the btool of some of the inputs that were enabled. The documentation stated if you didn't need to update the indexes then the default would work. That's what should be displayed below.
Sample inputs.conf:
C:Program FilesSplunkUniversalForwarderetcappsTA-DomainController-NT6defaultinputs.conf [WinEventLog:Key Management Service] C:Program FilesSplunkUniversalForwarderetcsystemdefaultinputs.conf _rcvbuf = 1572864 C:Program FilesSplunkUniversalForwarderetcappsTA-DNSServer-NT6defaultinputs.conf counters = C:Program FilesSplunkUniversalForwarderetcappsTA-DomainController-NT6defaultinputs.conf disabled = 0 C:Program FilesSplunkUniversalForwarderetcappsSplunk_TA_windowsdefaultinputs.conf evt_dc_name = C:Program FilesSplunkUniversalForwarderetcappsSplunk_TA_windowsdefaultinputs.conf evt_dns_name = C:Program FilesSplunkUniversalForwarderetcsystemdefaultinputs.conf evt_resolve_ad_obj = 0 C:Program FilesSplunkUniversalForwarderetcsystemlocalinputs.conf host = * C:Program FilesSplunkUniversalForwarderetcappsTA-DomainController-NT6defaultinputs.conf index = winevents C:Program FilesSplunkUniversalForwarderetcappsTA-DNSServer-NT6defaultinputs.conf instances = C:Program FilesSplunkUniversalForwarderetcappsTA-DNSServer-NT6defaultinputs.conf interval = 10 C:Program FilesSplunkUniversalForwarderetcappsTA-DNSServer-NT6defaultinputs.conf object = Processor C:Program FilesSplunkUniversalForwarderetcappsTA-DomainController-NT6defaultinputs.conf queue = parsingQueue C:Program FilesSplunkUniversalForwarderetcappsTA-DomainController-NT6defaultinputs.conf sourcetype = "WinEventLog:Key Management Service" C:Program FilesSplunkUniversalForwarderetcappsMSICreatedlocalinputs.conf [WinEventLog:Security] C:Program FilesSplunkUniversalForwarderetcsystemdefaultinputs.conf _rcvbuf = 1572864 C:Program FilesSplunkUniversalForwarderetcappsSplunk_TA_windowsdefaultinputs.conf checkpointInterval = 5 C:Program FilesSplunkUniversalForwarderetcappsTA-DNSServer-NT6defaultinputs.conf counters = C:Program FilesSplunkUniversalForwarderetcappsSplunk_TA_windowsdefaultinputs.conf current_only = 0 C:Program FilesSplunkUniversalForwarderetcappsMSICreatedlocalinputs.conf disabled = 0 C:Program FilesSplunkUniversalForwarderetcappsSplunk_TA_windowsdefaultinputs.conf evt_dc_name = C:Program FilesSplunkUniversalForwarderetcappsSplunk_TA_windowsdefaultinputs.conf evt_dns_name = C:Program FilesSplunkUniversalForwarderetcappsSplunk_TA_windowsdefaultinputs.conf evt_resolve_ad_obj = 1 C:Program FilesSplunkUniversalForwarderetcsystemlocalinputs.conf host = * C:Program FilesSplunkUniversalForwarderetcappsTA-DNSServer-NT6defaultinputs.conf index = perfmon C:Program FilesSplunkUniversalForwarderetcappsTA-DNSServer-NT6defaultinputs.conf instances = C:Program FilesSplunkUniversalForwarderetcappsTA-DNSServer-NT6defaultinputs.conf interval = 10 C:Program FilesSplunkUniversalForwarderetcappsTA-DNSServer-NT6defaultinputs.conf object = Processor C:Program FilesSplunkUniversalForwarderetcappsSplunk_TA_windowsdefaultinputs.conf start_from = oldest C:Program FilesSplunkUniversalForwarderetcappsMSICreatedlocalinputs.conf [WinEventLog:Setup] C:Program FilesSplunkUniversalForwarderetcsystemdefaultinputs.conf _rcvbuf = 1572864 C:Program FilesSplunkUniversalForwarderetcsystemdefaultinputs.conf checkpointInterval = 5 C:Program FilesSplunkUniversalForwarderetcappsTA-DNSServer-NT6defaultinputs.conf counters = C:Program FilesSplunkUniversalForwarderetcsystemdefaultinputs.conf current_only = 0 C:Program FilesSplunkUniversalForwarderetcsystemdefaultinputs.conf disabled = 1 C:Program FilesSplunkUniversalForwarderetcappsSplunk_TA_windowsdefaultinputs.conf evt_dc_name = C:Program FilesSplunkUniversalForwarderetcappsSplunk_TA_windowsdefaultinputs.conf evt_dns_name = C:Program FilesSplunkUniversalForwarderetcsystemdefaultinputs.conf evt_resolve_ad_obj = 0 C:Program FilesSplunkUniversalForwarderetcsystemlocalinputs.conf host = * C:Program FilesSplunkUniversalForwarderetcappsTA-DNSServer-NT6defaultinputs.conf index = perfmon C:Program FilesSplunkUniversalForwarderetcappsTA-DNSServer-NT6defaultinputs.conf instances = C:Program FilesSplunkUniversalForwarderetcappsTA-DNSServer-NT6defaultinputs.conf interval = 10 C:Program FilesSplunkUniversalForwarderetcappsTA-DNSServer-NT6defaultinputs.conf object = Processor C:Program FilesSplunkUniversalForwarderetcsystemdefaultinputs.conf start_from = oldest C:Program FilesSplunkUniversalForwarderetcappsMSICreatedlocalinputs.conf [WinEventLog:System] C:Program FilesSplunkUniversalForwarderetcsystemdefaultinputs.conf _rcvbuf = 1572864 C:Program FilesSplunkUniversalForwarderetcappsSplunk_TA_windowsdefaultinputs.conf checkpointInterval = 5 C:Program FilesSplunkUniversalForwarderetcappsTA-DNSServer-NT6defaultinputs.conf counters = C:Program FilesSplunkUniversalForwarderetcappsSplunk_TA_windowsdefaultinputs.conf current_only = 0 C:Program FilesSplunkUniversalForwarderetcappsMSICreatedlocalinputs.conf disabled = 0 C:Program FilesSplunkUniversalForwarderetcappsSplunk_TA_windowsdefaultinputs.conf evt_dc_name = C:Program FilesSplunkUniversalForwarderetcappsSplunk_TA_windowsdefaultinputs.conf evt_dns_name = C:Program FilesSplunkUniversalForwarderetcsystemdefaultinputs.conf evt_resolve_ad_obj = 0 C:Program FilesSplunkUniversalForwarderetcsystemlocalinputs.conf host = * C:Program FilesSplunkUniversalForwarderetcappsTA-DNSServer-NT6defaultinputs.conf index = perfmon C:Program FilesSplunkUniversalForwarderetcappsTA-DNSServer-NT6defaultinputs.conf instances = C:Program FilesSplunkUniversalForwarderetcappsTA-DNSServer-NT6defaultinputs.conf interval = 10 C:Program FilesSplunkUniversalForwarderetcappsTA-DNSServer-NT6defaultinputs.conf object = Processor C:Program FilesSplunkUniversalForwarderetcappsSplunk_TA_windowsdefaultinputs.conf start_from = oldest