<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic managing log.cfg through deployment server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/managing-log-cfg-through-deployment-server/m-p/180753#M36246</link>
    <description>&lt;P&gt;I am trying to minimize noise level (across WAN) by splunk to greatest degree possible.. &lt;/P&gt;

&lt;P&gt;With review of index=_internal source=splunkd, I see that each of my universal forwarders is forwarding lines from splunkd.log.  This log file is very noisy with most components logging INFO level events by default.  I want to change most of the logging levels to &amp;gt;= WARN.  &lt;/P&gt;

&lt;P&gt;I know this can be done by manually altering logging levels in .\etc\log.cfg.   Does anyone have any experience managing this configuration as a deployment-app?  I imagine it would be possible with deployment of a script to execute line changes.. Is this a bad idea?  &lt;/P&gt;

&lt;P&gt;inputs appreciated.&lt;/P&gt;</description>
    <pubDate>Tue, 17 Dec 2013 03:14:19 GMT</pubDate>
    <dc:creator>dstaulcu</dc:creator>
    <dc:date>2013-12-17T03:14:19Z</dc:date>
    <item>
      <title>managing log.cfg through deployment server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/managing-log-cfg-through-deployment-server/m-p/180753#M36246</link>
      <description>&lt;P&gt;I am trying to minimize noise level (across WAN) by splunk to greatest degree possible.. &lt;/P&gt;

&lt;P&gt;With review of index=_internal source=splunkd, I see that each of my universal forwarders is forwarding lines from splunkd.log.  This log file is very noisy with most components logging INFO level events by default.  I want to change most of the logging levels to &amp;gt;= WARN.  &lt;/P&gt;

&lt;P&gt;I know this can be done by manually altering logging levels in .\etc\log.cfg.   Does anyone have any experience managing this configuration as a deployment-app?  I imagine it would be possible with deployment of a script to execute line changes.. Is this a bad idea?  &lt;/P&gt;

&lt;P&gt;inputs appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2013 03:14:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/managing-log-cfg-through-deployment-server/m-p/180753#M36246</guid>
      <dc:creator>dstaulcu</dc:creator>
      <dc:date>2013-12-17T03:14:19Z</dc:date>
    </item>
    <item>
      <title>Re: managing log.cfg through deployment server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/managing-log-cfg-through-deployment-server/m-p/180754#M36247</link>
      <description>&lt;P&gt;Here is how I plan to package that solution as an app:&lt;/P&gt;

&lt;P&gt;Create a new app with following files:&lt;/P&gt;

&lt;P&gt;.\deployment-apps\UF-LogCfgMgr\bin\&lt;A href="http://pastebin.com/tDYiYAv0"&gt;logcfg.bat&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;.\deployment-apps\UF-LogCfgMgr\bin\&lt;A href="http://pastebin.com/XRy3g8Qg"&gt;logcfg.vbs&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;.\deployment-apps\UF-LogCfgMgr\local\&lt;A href="http://pastebin.com/2ma88cU4"&gt;inputs.conf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;12/28/2013 - Follow up.  Method worked.  Added condition to leave INFO logging levels to DEV/TEST deployment clients but to use WARN only for PROD deployment clients.&lt;/P&gt;

&lt;P&gt;1/19/2013 - updated logcfg.vbs to use log-local.cfg construct, to further tweak logging levels, to, and to support x86  on x64.  Supports windows only&lt;/P&gt;</description>
      <pubDate>Sat, 21 Dec 2013 20:35:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/managing-log-cfg-through-deployment-server/m-p/180754#M36247</guid>
      <dc:creator>dstaulcu</dc:creator>
      <dc:date>2013-12-21T20:35:36Z</dc:date>
    </item>
  </channel>
</rss>

