Hi,
I installed the universal forwarder agent on some servers for monitoring and would like to add a whitelist filter on the Windows security event.
When I add the "whitelist" line in the inputs.conf file in the "C: \ Program Files \ SplunkUniversalForwarder \ etc \ apps \ SplunkUniversalForwarder \ local" from the server that I installed the agent, the filter works.
As it is configured, I need to edit all the inputs.conf files on the servers that I installed the agent to add to the whitelist.
Is there any way to replicate the whitelist settings on the deployment server?
Thanks.
↧