<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can you explain Indexer functionality with inputs.conf configured for /var/log/? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-you-explain-Indexer-functionality-with-inputs-conf/m-p/377741#M68331</link>
    <description>&lt;P&gt;I have Indexers in a cluster running Splunk_TA_nix. I'm monitoring /var/log in inputs.conf. I can see the log events from the search head with a splunk_server from a different Indexer in the cluster. Two questions&lt;/P&gt;

&lt;P&gt;1) How did the /var/log/messages, as an example, get indexed? Did it get indexed locally, and if so, how did it know to do that? Or did the events get forwarded to other indexers in the cluster like how our heavy forwarders use Indexer-discovery by contacting the Cluster master for the list of indexers? I ask because I do not see any outputs.conf being configured on Indexers showing any auto-discovery. The cluster master settings are only in the server.conf file. I do not see how these local OS logs are being indexed and it's bothering me. &lt;/P&gt;

&lt;P&gt;2) Can I assume the search results showing the /var/log/messages from host1 being seen in the results as splunk_server=host2 is due to replication or is it from host1 forwarding to host2 for indexing?&lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 23:11:49 GMT</pubDate>
    <dc:creator>kmarciniak</dc:creator>
    <dc:date>2020-09-29T23:11:49Z</dc:date>
    <item>
      <title>Can you explain Indexer functionality with inputs.conf configured for /var/log/?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-you-explain-Indexer-functionality-with-inputs-conf/m-p/377741#M68331</link>
      <description>&lt;P&gt;I have Indexers in a cluster running Splunk_TA_nix. I'm monitoring /var/log in inputs.conf. I can see the log events from the search head with a splunk_server from a different Indexer in the cluster. Two questions&lt;/P&gt;

&lt;P&gt;1) How did the /var/log/messages, as an example, get indexed? Did it get indexed locally, and if so, how did it know to do that? Or did the events get forwarded to other indexers in the cluster like how our heavy forwarders use Indexer-discovery by contacting the Cluster master for the list of indexers? I ask because I do not see any outputs.conf being configured on Indexers showing any auto-discovery. The cluster master settings are only in the server.conf file. I do not see how these local OS logs are being indexed and it's bothering me. &lt;/P&gt;

&lt;P&gt;2) Can I assume the search results showing the /var/log/messages from host1 being seen in the results as splunk_server=host2 is due to replication or is it from host1 forwarding to host2 for indexing?&lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:11:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-you-explain-Indexer-functionality-with-inputs-conf/m-p/377741#M68331</guid>
      <dc:creator>kmarciniak</dc:creator>
      <dc:date>2020-09-29T23:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: Can you explain Indexer functionality with inputs.conf configured for /var/log/?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-you-explain-Indexer-functionality-with-inputs-conf/m-p/377742#M68332</link>
      <description>&lt;P&gt;The &lt;CODE&gt;splunk_server&lt;/CODE&gt; tells you which Indexer handled and stored the incoming event.  If the &lt;CODE&gt;host&lt;/CODE&gt; value for the event is the same, then the event got to the indexer because it was already on the indexer.  If the &lt;CODE&gt;host&lt;/CODE&gt; value is something else, then that server sent the events to the indexer, probably directly (but possibly indirectly); you need to see what is in the &lt;CODE&gt;outputs.conf&lt;/CODE&gt; files on the &lt;CODE&gt;host&lt;/CODE&gt;. &lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 22:10:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-you-explain-Indexer-functionality-with-inputs-conf/m-p/377742#M68332</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-02-08T22:10:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can you explain Indexer functionality with inputs.conf configured for /var/log/?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-you-explain-Indexer-functionality-with-inputs-conf/m-p/377743#M68333</link>
      <description>&lt;P&gt;1) The key differentiator here is the host is an "indexer" itself. I am monitoring /var/log/* via inputs.conf of the splunk_ta_nix. There are no configuration settings in the indexer's outputs.conf referencing any auto-discovery for its index cluster. So how did /var/log/messages get indexed? &lt;BR /&gt;
1) For indexers only, does setting an inputs.conf to monitor a file just magically get indexed locally with no outputs.conf file setting showing any destination?&lt;BR /&gt;
2) For indexers only, does the indexer just know to use auto-discovery since its part of the cluster environment and will then magically look at its server.conf for the CM and get its list of indexers to forward to and perhaps including itself?&lt;BR /&gt;
3) in my search results the indexer is host1 and the splunk_server was indexer host2 and indexer host3. &lt;/P&gt;

&lt;P&gt;I'm still perplexed as to how /var/log/messages from an indexer running splunk_TA_nix is getting indexed. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:11:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-you-explain-Indexer-functionality-with-inputs-conf/m-p/377743#M68333</guid>
      <dc:creator>kmarciniak</dc:creator>
      <dc:date>2020-09-29T23:11:52Z</dc:date>
    </item>
    <item>
      <title>Re: Can you explain Indexer functionality with inputs.conf configured for /var/log/?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-you-explain-Indexer-functionality-with-inputs-conf/m-p/377744#M68334</link>
      <description>&lt;P&gt;Some TAs are created with some settings enabled.  It looks like this one is created with some settings in the &lt;CODE&gt;inputs.conf&lt;/CODE&gt; file enabled.  It is easy to check.  Because the Indexer will index local files to itself, any &lt;CODE&gt;inputs.conf&lt;/CODE&gt; that has something that it can find, will be indexed, provided the splunk instance on the indexer has been restarted.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 22:33:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-you-explain-Indexer-functionality-with-inputs-conf/m-p/377744#M68334</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-02-08T22:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: Can you explain Indexer functionality with inputs.conf configured for /var/log/?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-you-explain-Indexer-functionality-with-inputs-conf/m-p/377745#M68335</link>
      <description>&lt;P&gt;What you just said "Because the Indexer will index local files to itself" is my question. So where is setting to automatically index local files to itself? This was the part i was wondering about. So if it indexes local files to itself such as /var/log/messages from the Splunk_TA_nix where is this setting? Or do you just take it for granted? &lt;BR /&gt;
Also, if the indexer is indexing its local files from any inputs.conf automatically, then if I run a search for these events in indexer host1 i see splunk_server showing different indexers host2 and host3. Does this mean the indexed data from host1 was replicated over to other indexers and the search just happened to use the data from host2 and host 3 instead of host1?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:11:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-you-explain-Indexer-functionality-with-inputs-conf/m-p/377745#M68335</guid>
      <dc:creator>kmarciniak</dc:creator>
      <dc:date>2020-09-29T23:11:54Z</dc:date>
    </item>
  </channel>
</rss>

