<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cluster indexes.conf  -&amp;gt; inputs.conf  -&amp;gt; App -&amp;gt; serverClass confusion in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Cluster-indexes-conf-gt-inputs-conf-gt-App-gt-serverClass/m-p/612684#M106007</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/54774"&gt;@jcorcoran508&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the choose to have the same or two different indexes for Production and not production, usually depends on two factors:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;the data retention,&lt;/LI&gt;&lt;LI&gt;the access rights.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;if the Non Prod data must be conserved for the same time of the Prod data and the people that have to access&amp;nbsp; are the same you can use the same index, otherwise you need to use different indexes, usually two different indexes are used!&lt;/P&gt;&lt;P&gt;Also because using one index you have to add to your searches the filter Prod/nonProd.&lt;/P&gt;&lt;P&gt;About inputs.conf, you have to create two apps to deploy using two different ServerClasses in the Deployment Server: each app contains an inputs.conf with the correct index to send data.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 12 Sep 2022 06:44:36 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-09-12T06:44:36Z</dc:date>
    <item>
      <title>Cluster indexes.conf  -&gt; inputs.conf  -&gt; App -&gt; serverClass confusion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cluster-indexes-conf-gt-inputs-conf-gt-App-gt-serverClass/m-p/612670#M106005</link>
      <description>&lt;P&gt;I am creating an index - configured the inputs.conf file.&lt;/P&gt;
&lt;P&gt;I have two prod servers with app logs that have the same Linux path&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Additionally, I have two test servers (Non-Prod) both had the same linux log paths , but different from the prod servers.&lt;/P&gt;
&lt;P&gt;Besides hard coding the servers in the inputs.conf file how does the process determine what host to collect the log data from identical paths listed in the inputs.conf&lt;/P&gt;
&lt;P&gt;some questions:&lt;/P&gt;
&lt;P&gt;Can I use the same index with prod and non prod (best practice ?)&lt;/P&gt;
&lt;P&gt;So the inputs.conf has the index=x under the log stanza name&amp;nbsp; , so that maps the inputs.conf file to collect the data and the data belongs to index=x.&lt;/P&gt;
&lt;P&gt;In the deployment I create a serverClass with all 4 servers (prod and non prod)&lt;/P&gt;
&lt;P&gt;and assign the server class to the App that has inputs.conf file.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Should I be creating separate indexes (prod and non-prod) then create separate&amp;nbsp; Apps (prod and non-prod)&amp;nbsp; then create separate ServerClasses (prod and non prod) ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2022 11:56:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cluster-indexes-conf-gt-inputs-conf-gt-App-gt-serverClass/m-p/612670#M106005</guid>
      <dc:creator>jcorcoran508</dc:creator>
      <dc:date>2022-09-12T11:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: cluster indexes.conf  -&gt; inputs.conf  -&gt; App -&gt; serverClass confusion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cluster-indexes-conf-gt-inputs-conf-gt-App-gt-serverClass/m-p/612684#M106007</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/54774"&gt;@jcorcoran508&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the choose to have the same or two different indexes for Production and not production, usually depends on two factors:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;the data retention,&lt;/LI&gt;&lt;LI&gt;the access rights.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;if the Non Prod data must be conserved for the same time of the Prod data and the people that have to access&amp;nbsp; are the same you can use the same index, otherwise you need to use different indexes, usually two different indexes are used!&lt;/P&gt;&lt;P&gt;Also because using one index you have to add to your searches the filter Prod/nonProd.&lt;/P&gt;&lt;P&gt;About inputs.conf, you have to create two apps to deploy using two different ServerClasses in the Deployment Server: each app contains an inputs.conf with the correct index to send data.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2022 06:44:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cluster-indexes-conf-gt-inputs-conf-gt-App-gt-serverClass/m-p/612684#M106007</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-12T06:44:36Z</dc:date>
    </item>
  </channel>
</rss>

