<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: configuration files in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/configuration-files/m-p/687324#M19379</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Inputs.conf &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;One of the objectives is for you add data into Splunk via a configuration mechanism, typically this is via an inputs.conf file, so if you have logs you want to add to splunk then you would use inputs.conf as a simple example. There are other use case settings as well such as setting the Splunk server's receiver settings as well - see the below link for further examples and use cases. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.1/Admin/Inputsconf#inputs.conf.example" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.2.1/Admin/Inputsconf#inputs.conf.example&lt;/A&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;web.conf &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The main object is to configure the Splunk Web settings (HTTP/HTTPS) / security settings - this is set with TLS &amp;nbsp;certificates for production environment’s &amp;nbsp;- you can see the examples in the below link &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.1/admin/Webconf#web.conf.example" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.2.1/admin/Webconf#web.conf.example&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;You can&amp;nbsp; and should create sperate apps, example my_linux_secure_logs and place the inputs.conf there (You can’t change the names of the conf files.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;There is a good app folder diagram here to show you where files and folders live - and you have to follow this structure with the config files you need.&amp;nbsp;&lt;BR /&gt;&lt;A href="https://dev.splunk.com/enterprise/docs/developapps/createapps/appanatomy/" target="_blank"&gt;https://dev.splunk.com/enterprise/docs/developapps/createapps/appanatomy/&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In terms of app precedency, order is based on the lexicographical (alphabetical) order of the app names under global context. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Simple example App A (my_app_a) &amp;nbsp;will be before App B (my_app_b) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Have a look at the concepts below &amp;nbsp;on app precedency &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.1/Admin/Wheretofindtheconfigurationfiles" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.2.1/Admin/Wheretofindtheconfigurationfiles&lt;/A&gt; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 13 May 2024 12:14:13 GMT</pubDate>
    <dc:creator>deepakc</dc:creator>
    <dc:date>2024-05-13T12:14:13Z</dc:date>
    <item>
      <title>configuration files</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/configuration-files/m-p/687297#M19373</link>
      <description>&lt;P&gt;Explain me construction structure of configuration file in splunk and what all component it contain and what we call them.&amp;nbsp;&lt;/P&gt;&lt;P&gt;[what are imp configuration files in splunk, what is the purpose of these diffenet files. If a file suppose inputs.conf is present in multiple apps then how splunk will consolidate it. what is the file precedency order. can i have my own configuration file name like my nameinputs.conf file, will it work and how.]&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 08:13:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/configuration-files/m-p/687297#M19373</guid>
      <dc:creator>bucky12</dc:creator>
      <dc:date>2024-05-13T08:13:30Z</dc:date>
    </item>
    <item>
      <title>Re: configuration files</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/configuration-files/m-p/687299#M19374</link>
      <description>&lt;P&gt;This is a broad question. What is your specific usecase that you are trying to solve?&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 08:19:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/configuration-files/m-p/687299#M19374</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-05-13T08:19:05Z</dc:date>
    </item>
    <item>
      <title>Re: configuration files</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/configuration-files/m-p/687307#M19375</link>
      <description>&lt;P&gt;inputs.conf web.conf. what is the purpose of these files&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 09:30:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/configuration-files/m-p/687307#M19375</guid>
      <dc:creator>bucky12</dc:creator>
      <dc:date>2024-05-13T09:30:44Z</dc:date>
    </item>
    <item>
      <title>Re: configuration files</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/configuration-files/m-p/687324#M19379</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Inputs.conf &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;One of the objectives is for you add data into Splunk via a configuration mechanism, typically this is via an inputs.conf file, so if you have logs you want to add to splunk then you would use inputs.conf as a simple example. There are other use case settings as well such as setting the Splunk server's receiver settings as well - see the below link for further examples and use cases. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.1/Admin/Inputsconf#inputs.conf.example" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.2.1/Admin/Inputsconf#inputs.conf.example&lt;/A&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;web.conf &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The main object is to configure the Splunk Web settings (HTTP/HTTPS) / security settings - this is set with TLS &amp;nbsp;certificates for production environment’s &amp;nbsp;- you can see the examples in the below link &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.1/admin/Webconf#web.conf.example" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.2.1/admin/Webconf#web.conf.example&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;You can&amp;nbsp; and should create sperate apps, example my_linux_secure_logs and place the inputs.conf there (You can’t change the names of the conf files.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;There is a good app folder diagram here to show you where files and folders live - and you have to follow this structure with the config files you need.&amp;nbsp;&lt;BR /&gt;&lt;A href="https://dev.splunk.com/enterprise/docs/developapps/createapps/appanatomy/" target="_blank"&gt;https://dev.splunk.com/enterprise/docs/developapps/createapps/appanatomy/&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In terms of app precedency, order is based on the lexicographical (alphabetical) order of the app names under global context. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Simple example App A (my_app_a) &amp;nbsp;will be before App B (my_app_b) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Have a look at the concepts below &amp;nbsp;on app precedency &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.1/Admin/Wheretofindtheconfigurationfiles" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.2.1/Admin/Wheretofindtheconfigurationfiles&lt;/A&gt; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 12:14:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/configuration-files/m-p/687324#M19379</guid>
      <dc:creator>deepakc</dc:creator>
      <dc:date>2024-05-13T12:14:13Z</dc:date>
    </item>
  </channel>
</rss>

