<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: difference between /splunk/etc/system/local and /splunk/etc/apps/search/local in Security</title>
    <link>https://community.splunk.com/t5/Security/difference-between-splunk-etc-system-local-and-splunk-etc-apps/m-p/21943#M13687</link>
    <description>&lt;P&gt;spent too much time editing...&lt;/P&gt;</description>
    <pubDate>Thu, 02 May 2013 06:36:40 GMT</pubDate>
    <dc:creator>kristian_kolb</dc:creator>
    <dc:date>2013-05-02T06:36:40Z</dc:date>
    <item>
      <title>difference between /splunk/etc/system/local and /splunk/etc/apps/search/local</title>
      <link>https://community.splunk.com/t5/Security/difference-between-splunk-etc-system-local-and-splunk-etc-apps/m-p/21941#M13685</link>
      <description>&lt;P&gt;Hi, everybody.&lt;/P&gt;

&lt;P&gt;What`s the difference between /splunk/etc/system/local and /splunk/etc/apps/search/local？&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2013 06:17:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/difference-between-splunk-etc-system-local-and-splunk-etc-apps/m-p/21941#M13685</guid>
      <dc:creator>perlish</dc:creator>
      <dc:date>2013-05-02T06:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: difference between /splunk/etc/system/local and /splunk/etc/apps/search/local</title>
      <link>https://community.splunk.com/t5/Security/difference-between-splunk-etc-system-local-and-splunk-etc-apps/m-p/21942#M13686</link>
      <description>&lt;P&gt;You should read this page: &lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/admin/Wheretofindtheconfigurationfiles"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.2/admin/Wheretofindtheconfigurationfiles&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Basically the former is the system default directory, which is the sort of base layer of the whole config system, and which can be overridden by several higher-precedence layer. &lt;/P&gt;

&lt;P&gt;and the latter is the "local" directory of the search app's configuration layer.   Which can be overridden by user-level config,  but which itself  overrides the search app's "default" config as well as all the "system" config, at least when you're in the search app. &lt;/P&gt;

&lt;P&gt;but again, the real answers are all on this page:  &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/admin/Wheretofindtheconfigurationfiles"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.2/admin/Wheretofindtheconfigurationfiles&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2013 06:26:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/difference-between-splunk-etc-system-local-and-splunk-etc-apps/m-p/21942#M13686</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2013-05-02T06:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: difference between /splunk/etc/system/local and /splunk/etc/apps/search/local</title>
      <link>https://community.splunk.com/t5/Security/difference-between-splunk-etc-system-local-and-splunk-etc-apps/m-p/21943#M13687</link>
      <description>&lt;P&gt;spent too much time editing...&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2013 06:36:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/difference-between-splunk-etc-system-local-and-splunk-etc-apps/m-p/21943#M13687</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-05-02T06:36:40Z</dc:date>
    </item>
  </channel>
</rss>

