<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: system local folder vs forwarder local folder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/system-local-folder-vs-forwarder-local-folder/m-p/176285#M35345</link>
    <description>&lt;P&gt;This should add some clarity: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.3/admin/Wheretofindtheconfigurationfiles"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.3/admin/Wheretofindtheconfigurationfiles&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Jun 2015 09:40:37 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2015-06-26T09:40:37Z</dc:date>
    <item>
      <title>system local folder vs forwarder local folder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/system-local-folder-vs-forwarder-local-folder/m-p/176283#M35343</link>
      <description>&lt;P&gt;In Heavyforwader if we go to SYSTEM directory we have Local and  Default directories created by it self in which we have all the configuration files by default like( inputs.conf , output.conf , props.conf , transforms.conf , etc.,)&lt;/P&gt;

&lt;P&gt;Now my question is why to enable SplunkForwarder for  local directory and manually create all the configuration files  (input.conf , output.conf, props.conf and transforms.conf ) ? and transfer the log data same as universal forwarder&lt;/P&gt;

&lt;P&gt;why cant we forward the log data directly from system--&amp;gt;local directory to enterprise server...&lt;/P&gt;

&lt;P&gt;plz correct me if there is any wrong.....&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2015 17:14:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/system-local-folder-vs-forwarder-local-folder/m-p/176283#M35343</guid>
      <dc:creator>splunkatl</dc:creator>
      <dc:date>2015-06-25T17:14:54Z</dc:date>
    </item>
    <item>
      <title>Re: system local folder vs forwarder local folder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/system-local-folder-vs-forwarder-local-folder/m-p/176284#M35344</link>
      <description>&lt;P&gt;The directory structure for indexers, heavy forwarders and universal forwarders is the same. You can put configuration files in &lt;CODE&gt;SPLUNK_HOME/etc/system/local&lt;/CODE&gt; or you can put them in an app &lt;CODE&gt;SPLUNK_HOME/etc/apps/AppName/local&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;You should only create or edit files in the &lt;CODE&gt;local&lt;/CODE&gt; subdirectories. Never change the files in the &lt;CODE&gt;default&lt;/CODE&gt; subdirectories.&lt;/P&gt;

&lt;P&gt;For indexers, heavy forwarders and universal forwarders, the BEST PRACTICE is the same: put your configurations in an app directory &lt;CODE&gt;SPLUNK_HOME/etc/apps/AppName/local&lt;/CODE&gt; not the system-level directories. This makes your configurations easier to manage.  Many people use the "search" app directory for general configurations. Config files such as inputs.conf, outputs.conf, deploymentclient.conf, props.conf and transforms.conf should be placed in an app-level directory.&lt;/P&gt;

&lt;P&gt;The only configurations that SHOULD go into the &lt;CODE&gt;SPLUNK_HOME/etc/system/local&lt;/CODE&gt;directory are true system settings such as the host name setting (in server.conf) and port numbers (in web.conf and server.conf).&lt;/P&gt;

&lt;P&gt;If you follow the best practice, then it is easy to copy the entire app from one system to another, and the systems will be configured the same.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2015 06:25:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/system-local-folder-vs-forwarder-local-folder/m-p/176284#M35344</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2015-06-26T06:25:49Z</dc:date>
    </item>
    <item>
      <title>Re: system local folder vs forwarder local folder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/system-local-folder-vs-forwarder-local-folder/m-p/176285#M35345</link>
      <description>&lt;P&gt;This should add some clarity: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.3/admin/Wheretofindtheconfigurationfiles"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.3/admin/Wheretofindtheconfigurationfiles&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2015 09:40:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/system-local-folder-vs-forwarder-local-folder/m-p/176285#M35345</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2015-06-26T09:40:37Z</dc:date>
    </item>
  </channel>
</rss>

