<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic how does splunk handle multiple indexes.conf files with volume definitions? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/how-does-splunk-handle-multiple-indexes-conf-files-with-volume/m-p/76098#M15539</link>
    <description>&lt;P&gt;I hope this is simple. Most conf files in Splunk, when overlapping in multiple apps, get essentially appended together at runtime. That may be an over simplification but it is the easiest way to understand it for me. How does this function for indexes.conf? Specifically, can I create an indexes.conf file to be included with a deployment client app that includes volume definitions (setting the size of hot and cold) that are common to all indexers, and then when we deploy other apps to my indexers, include a supplementary indexes.conf which only defines new indexes, and whose definitions refer to the hot and cold volumes defined in the deployment client, but don't themselves contain the volume definition? We must use volume definitions instead of static index sizes due to constantly changing source data specifications and the amount of data we deal with.&lt;/P&gt;

&lt;P&gt;Any advice would be appreciated. I am hoping this isn't a rtfm type thing but I couldn't find the answer in the docs.&lt;/P&gt;</description>
    <pubDate>Wed, 26 Jun 2013 12:04:54 GMT</pubDate>
    <dc:creator>msarro</dc:creator>
    <dc:date>2013-06-26T12:04:54Z</dc:date>
    <item>
      <title>how does splunk handle multiple indexes.conf files with volume definitions?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-does-splunk-handle-multiple-indexes-conf-files-with-volume/m-p/76098#M15539</link>
      <description>&lt;P&gt;I hope this is simple. Most conf files in Splunk, when overlapping in multiple apps, get essentially appended together at runtime. That may be an over simplification but it is the easiest way to understand it for me. How does this function for indexes.conf? Specifically, can I create an indexes.conf file to be included with a deployment client app that includes volume definitions (setting the size of hot and cold) that are common to all indexers, and then when we deploy other apps to my indexers, include a supplementary indexes.conf which only defines new indexes, and whose definitions refer to the hot and cold volumes defined in the deployment client, but don't themselves contain the volume definition? We must use volume definitions instead of static index sizes due to constantly changing source data specifications and the amount of data we deal with.&lt;/P&gt;

&lt;P&gt;Any advice would be appreciated. I am hoping this isn't a rtfm type thing but I couldn't find the answer in the docs.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2013 12:04:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-does-splunk-handle-multiple-indexes-conf-files-with-volume/m-p/76098#M15539</guid>
      <dc:creator>msarro</dc:creator>
      <dc:date>2013-06-26T12:04:54Z</dc:date>
    </item>
    <item>
      <title>Re: how does splunk handle multiple indexes.conf files with volume definitions?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-does-splunk-handle-multiple-indexes-conf-files-with-volume/m-p/76099#M15540</link>
      <description>&lt;P&gt;Yes you can , File precedence is as follows: &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;System local directory -- highest priority&lt;/LI&gt;
&lt;LI&gt;App local directories&lt;/LI&gt;
&lt;LI&gt;App default directories&lt;/LI&gt;
&lt;LI&gt;System default directory -- lowest priority&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.3/Admin/Wheretofindtheconfigurationfiles"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.3/Admin/Wheretofindtheconfigurationfiles&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2013 13:33:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-does-splunk-handle-multiple-indexes-conf-files-with-volume/m-p/76099#M15540</guid>
      <dc:creator>JSapienza</dc:creator>
      <dc:date>2013-06-26T13:33:41Z</dc:date>
    </item>
  </channel>
</rss>

