<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: When I edit inputs.conf and outputs.conf using the cli command, is there a reason why the paths to the modified file in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/When-I-edit-inputs-conf-and-outputs-conf-using-the-cli-command/m-p/672897#M112701</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello. Thank you very much for your kind reply.&lt;/P&gt;&lt;P&gt;May I ask one more question?&lt;/P&gt;&lt;P&gt;I understood what you were saying to mean that it is more appropriate to directly update the .conf file under $SPLUNK_HOME/etc/apps/&amp;lt;your_app&amp;gt;/local and manage it as a distribution server rather than using the add command.&lt;/P&gt;&lt;P&gt;Is there a reason why you don't recommend writing to the $SPLUNK_HOME/etc/system/local folder?&lt;/P&gt;</description>
    <pubDate>Sat, 30 Dec 2023 12:07:32 GMT</pubDate>
    <dc:creator>munang</dc:creator>
    <dc:date>2023-12-30T12:07:32Z</dc:date>
    <item>
      <title>When I edit inputs.conf and outputs.conf using the cli command, is there a reason why the paths to the modified files ar</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-I-edit-inputs-conf-and-outputs-conf-using-the-cli-command/m-p/672894#M112699</link>
      <description>&lt;P&gt;If I use the command ./splunk add monitor /var/log,&lt;/P&gt;&lt;P&gt;-&amp;gt; /splunk/etc/apps/search/local/inputs.conf file will be modified.&lt;/P&gt;&lt;P&gt;However, if I use the command ./splunk add forward-server a.a.a.a:9997,&lt;/P&gt;&lt;P&gt;-&amp;gt; /splunk/etc/system/local/outputs.conf is modified.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why are both the same cli tasks, but one modifies the file under the search app and the other modifies the system file?&lt;/P&gt;&lt;P&gt;Even considering the priority of the conf configuration file, both are GLOBAL CONTEXT, so I think they should both be placed under the System folder.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question may be inappropriate or may have some shortcomings. I would really appreciate your advice.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Dec 2023 04:14:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-I-edit-inputs-conf-and-outputs-conf-using-the-cli-command/m-p/672894#M112699</guid>
      <dc:creator>munang</dc:creator>
      <dc:date>2023-12-30T04:14:33Z</dc:date>
    </item>
    <item>
      <title>Re: When I edit inputs.conf and outputs.conf using the cli command, is there a reason why the paths to the modified file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-I-edit-inputs-conf-and-outputs-conf-using-the-cli-command/m-p/672895#M112700</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248607"&gt;@munang&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the command is always the same (splunk) bt the action is a different action, recorded ina different conf file:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;./splunk add monitor /var/log adda new input and inputs are recorded in the inputs.conf file,&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;./splunk add forward-server a.a.a.a:9997 ad a new destination and it's recorded in outputs.conf.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;In other words, the "splunk add" command updates a conf file, but the updated conf file depends on the object to update (inputs, outputs and so on).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I hope to be sufficiently clear.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Anyway, instead of using CLI commands, that writes updated in the $SPLUNK_HOME/etc/system/local folder, make your updates directly in the conf files in dedicated apps in $SPLUNK_HOME/etc/apps/&amp;lt;your_app&amp;gt;/local, so you can manage them using the Deployment Server (DS cannot manage conf files in&amp;nbsp;$SPLUNK_HOME/etc/system/local).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Dec 2023 07:23:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-I-edit-inputs-conf-and-outputs-conf-using-the-cli-command/m-p/672895#M112700</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-12-30T07:23:50Z</dc:date>
    </item>
    <item>
      <title>Re: When I edit inputs.conf and outputs.conf using the cli command, is there a reason why the paths to the modified file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-I-edit-inputs-conf-and-outputs-conf-using-the-cli-command/m-p/672897#M112701</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello. Thank you very much for your kind reply.&lt;/P&gt;&lt;P&gt;May I ask one more question?&lt;/P&gt;&lt;P&gt;I understood what you were saying to mean that it is more appropriate to directly update the .conf file under $SPLUNK_HOME/etc/apps/&amp;lt;your_app&amp;gt;/local and manage it as a distribution server rather than using the add command.&lt;/P&gt;&lt;P&gt;Is there a reason why you don't recommend writing to the $SPLUNK_HOME/etc/system/local folder?&lt;/P&gt;</description>
      <pubDate>Sat, 30 Dec 2023 12:07:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-I-edit-inputs-conf-and-outputs-conf-using-the-cli-command/m-p/672897#M112701</guid>
      <dc:creator>munang</dc:creator>
      <dc:date>2023-12-30T12:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: When I edit inputs.conf and outputs.conf using the cli command, is there a reason why the paths to the modified file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-I-edit-inputs-conf-and-outputs-conf-using-the-cli-command/m-p/672898#M112702</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I don’t know why those inputs and outputs conf are placed to different places with same splunk cli command. Maybe someone from splunk dev can tell that.&lt;BR /&gt;It’s a best practice to use/create your own apps to collect configurations of one app/issue to one place. Then you could/should put it into git and get version control on place. You could also utilize deployment server/manager node/deployer tp distribute it to correct places. You cannot use those tools with files under etc/system/local.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Sat, 30 Dec 2023 12:44:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-I-edit-inputs-conf-and-outputs-conf-using-the-cli-command/m-p/672898#M112702</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-12-30T12:44:16Z</dc:date>
    </item>
    <item>
      <title>Re: When I edit inputs.conf and outputs.conf using the cli command, is there a reason why the paths to the modified file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-I-edit-inputs-conf-and-outputs-conf-using-the-cli-command/m-p/672902#M112703</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248607"&gt;@munang&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;as I said, the best approach is to manage all Forwarders (Universal and Heavy) using the Deployment Server.&lt;/P&gt;&lt;P&gt;It's a best practive to manage with the DS all the inputs (in apps), but also other configurations as outputs.conf (addressing the Indexers) or deploymentclient.conf (addressing the Deployment Server).&lt;/P&gt;&lt;P&gt;The problem is that DS can mange only conf files in the $SPLUNK_HOME/etc/apps folder, so it cannot manage conf files in $SPLUNK_HOME/etc/system/local.&lt;/P&gt;&lt;P&gt;It's important to manage all Forwarders using the DS especially&amp;nbsp; when you have very many of them, and all configurations: e.g. if you have to add an Indexer or change the DS: if you have these conf files in a custom app, you can easily change them by the DS, if instead they are in $SPLUNK_HOME/etc/system/local, you have to manualy update them.&lt;/P&gt;&lt;P&gt;I usually create a custom app (called e.g. TA_Forwarders) containing three conf files:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;app.conf: describing the name and the purpose of the app,&lt;/LI&gt;&lt;LI&gt;outputs.conf: addressing the Indexers,&lt;/LI&gt;&lt;LI&gt;deploymentclient.conf: addressin g the Deployment Server.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sun, 31 Dec 2023 09:01:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-I-edit-inputs-conf-and-outputs-conf-using-the-cli-command/m-p/672902#M112703</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-12-31T09:01:28Z</dc:date>
    </item>
  </channel>
</rss>

