<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Spunk indexes.conf by deployment server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437503#M94668</link>
    <description>&lt;P&gt;Please share indexes.conf location on deployment server&lt;/P&gt;</description>
    <pubDate>Wed, 06 Jun 2018 11:33:11 GMT</pubDate>
    <dc:creator>lmjoin</dc:creator>
    <dc:date>2018-06-06T11:33:11Z</dc:date>
    <item>
      <title>Splunk indexes.conf by deployment server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437493#M94658</link>
      <description>&lt;P&gt;I have installed search head cluster and want pushing configuration by deployment server . But unable to find how to make and push indexes.conf to all indexers ( not in clustering ) . Thanks for reply in advance&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 22:55:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437493#M94658</guid>
      <dc:creator>lmjoin</dc:creator>
      <dc:date>2025-01-30T22:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: Spunk indexes.conf by deployment server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437494#M94659</link>
      <description>&lt;P&gt;Best practice would be to turn your indexers into an indexer cluster, and then push configuration to your indexers from the cluster master.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jun 2018 12:14:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437494#M94659</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2018-06-05T12:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: Spunk indexes.conf by deployment server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437495#M94660</link>
      <description>&lt;P&gt;That is true  , here we need such configuration.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jun 2018 12:21:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437495#M94660</guid>
      <dc:creator>lmjoin</dc:creator>
      <dc:date>2018-06-05T12:21:06Z</dc:date>
    </item>
    <item>
      <title>Re: Spunk indexes.conf by deployment server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437496#M94661</link>
      <description>&lt;P&gt;We need to do here by deployment server &lt;/P&gt;</description>
      <pubDate>Tue, 05 Jun 2018 12:30:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437496#M94661</guid>
      <dc:creator>lmjoin</dc:creator>
      <dc:date>2018-06-05T12:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: Spunk indexes.conf by deployment server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437497#M94662</link>
      <description>&lt;P&gt;You can configure indexers to be deployment clients of your deployment server, but that's kinda what the cluster master is there for. For example, the cluster master will trigger a rolling restart when new configuration requires a restart - some indexers will always be there. The deployment server will cause all indexers to restart, possibly at the same time.&lt;/P&gt;

&lt;P&gt;Who says you need to configure your indexers by deployment server? Ask them why you're not allowed to use best practices, and if they'll take responsibility when the entire indexing tier is down at the same time after a small configuration change.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jun 2018 12:44:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437497#M94662</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2018-06-05T12:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: Spunk indexes.conf by deployment server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437498#M94663</link>
      <description>&lt;P&gt;If you're certain you need indexers as deployment clients (hint: you don't, you want a cluster) then you can turn on their deployment client the same way you turn it on for forwarders: via the CLI &lt;CODE&gt;splunk set deploy-poll host:port&lt;/CODE&gt; or via deploymentclient.conf&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jun 2018 14:30:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437498#M94663</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2018-06-05T14:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: Spunk indexes.conf by deployment server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437499#M94664</link>
      <description>&lt;P&gt;thanks for reply , how to do entry in which file for same&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 07:04:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437499#M94664</guid>
      <dc:creator>lmjoin</dc:creator>
      <dc:date>2018-06-06T07:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: Spunk indexes.conf by deployment server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437500#M94665</link>
      <description>&lt;P&gt;Hi lmjoin!&lt;/P&gt;

&lt;P&gt;So you can push your indexes.conf from deployment server but make sure you include a metadata config file so that configuration is exported to system.&lt;/P&gt;

&lt;P&gt;In the app you will use for indexes make a folder called metadata and add a local.meta file into it containing the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;# Application-level permissions
[]
access = read : [ * ], write : [ admin]
export = system
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Let me know if that works out for you!&lt;/P&gt;

&lt;P&gt;Best regards,&lt;BR /&gt;
David&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 08:26:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437500#M94665</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2018-06-06T08:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: Spunk indexes.conf by deployment server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437501#M94666</link>
      <description>&lt;P&gt;ALL&lt;BR /&gt;
INDEXERS&lt;BR /&gt;
[serverClass:all_indexer]&lt;/P&gt;

&lt;H1&gt;whitelist.0&lt;/H1&gt;

&lt;P&gt;HN&lt;/P&gt;

&lt;H1&gt;whitelist.1&lt;/H1&gt;

&lt;P&gt;HN&lt;/P&gt;

&lt;H1&gt;whitelist.2&lt;/H1&gt;

&lt;P&gt;HN&lt;/P&gt;

&lt;H1&gt;whitelist.3&lt;/H1&gt;

&lt;P&gt;ALPD835.aldc.att.com&lt;/P&gt;

&lt;H1&gt;whitelist.4&lt;/H1&gt;

&lt;P&gt;ALPD836.aldc.att.com&lt;/P&gt;

&lt;H1&gt;restartSplunkd&lt;/H1&gt;

&lt;P&gt;true&lt;BR /&gt;
[serverClass:all_indexer:app:ito_det_deploymentclient]&lt;BR /&gt;
[serverClass:all_indexer:app:ito_det_indexer_base]&lt;BR /&gt;
[serverClass:all_indexer:app:ito_det_indexes]&lt;BR /&gt;
[serverClass:all_indexer:app:ito_det_license_slave]&lt;BR /&gt;
[serverClass:all_indexer:app:ito_det_dbx_timezone]&lt;BR /&gt;
[serverClass:all_indexer:app:Splunk_TA_nix]&lt;BR /&gt;
[serverClass:all_indexer:app:TA-­‐sos]&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:55:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437501#M94666</guid>
      <dc:creator>lmjoin</dc:creator>
      <dc:date>2020-09-29T19:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: Spunk indexes.conf by deployment server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437502#M94667</link>
      <description>&lt;P&gt;i have what to add in serverclass.conf for indexers but unable to make to find location where i put indexes.conf for &lt;/P&gt;

&lt;P&gt;ALL&lt;BR /&gt;
INDEXERS&lt;BR /&gt;
[serverClass:all_indexer]&lt;/P&gt;

&lt;H1&gt;whitelist.0&lt;/H1&gt;

&lt;P&gt;Hostname&lt;/P&gt;

&lt;H1&gt;whitelist.1&lt;/H1&gt;

&lt;P&gt;Hostname&lt;/P&gt;

&lt;H1&gt;whitelist.2&lt;/H1&gt;

&lt;P&gt;Hostname&lt;/P&gt;

&lt;H1&gt;whitelist.3&lt;/H1&gt;

&lt;P&gt;Hostname&lt;/P&gt;

&lt;H1&gt;whitelist.4&lt;/H1&gt;

&lt;P&gt;Hostname&lt;/P&gt;

&lt;H1&gt;restartSplunkd&lt;/H1&gt;

&lt;P&gt;true&lt;BR /&gt;
[serverClass:all_indexer:app:ito_det_deploymentclient]&lt;BR /&gt;
[serverClass:all_indexer:app:ito_det_indexer_base]&lt;BR /&gt;
[serverClass:all_indexer:app:ito_det_indexes]&lt;BR /&gt;
[serverClass:all_indexer:app:ito_det_license_slave]&lt;BR /&gt;
[serverClass:all_indexer:app:ito_det_dbx_timezone]&lt;BR /&gt;
[serverClass:all_indexer:app:Splunk_TA_nix]&lt;BR /&gt;
[serverClass:all_indexer:app:TA-­‐sos]&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:55:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437502#M94667</guid>
      <dc:creator>lmjoin</dc:creator>
      <dc:date>2020-09-29T19:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: Spunk indexes.conf by deployment server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437503#M94668</link>
      <description>&lt;P&gt;Please share indexes.conf location on deployment server&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 11:33:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437503#M94668</guid>
      <dc:creator>lmjoin</dc:creator>
      <dc:date>2018-06-06T11:33:11Z</dc:date>
    </item>
    <item>
      <title>Re: Spunk indexes.conf by deployment server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437504#M94669</link>
      <description>&lt;P&gt;so you have to put indexes.conf in an application on $SPLUNK_HOME/etc/deployment-apps/&lt;STRONG&gt;YOURAPP&lt;/STRONG&gt;/local this app needs to be pushed from the deployment server to the indexer that needs to be configured as a deployment client.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 12:26:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437504#M94669</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2018-06-06T12:26:07Z</dc:date>
    </item>
    <item>
      <title>Re: Spunk indexes.conf by deployment server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437505#M94670</link>
      <description>&lt;P&gt;@lmjoin, you don't need to edit your severclass manually. When you add your app to deployment-apps you can see it on the graphic interface under forwarder management on the deployment server. From there you can create the serverclass via GUI and add the app with indexes.conf in it and the indexers you wish to send it to &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 17:00:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437505#M94670</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2018-06-06T17:00:19Z</dc:date>
    </item>
    <item>
      <title>Re: Spunk indexes.conf by deployment server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437506#M94671</link>
      <description>&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.1/Updating/Aboutdeploymentserver"&gt;http://docs.splunk.com/Documentation/Splunk/7.1.1/Updating/Aboutdeploymentserver&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 18:42:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437506#M94671</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2018-06-06T18:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: Spunk indexes.conf by deployment server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437507#M94672</link>
      <description>&lt;P&gt;ok thanks , i will try and back&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 12:13:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437507#M94672</guid>
      <dc:creator>lmjoin</dc:creator>
      <dc:date>2018-06-07T12:13:48Z</dc:date>
    </item>
    <item>
      <title>Re: Spunk indexes.conf by deployment server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437508#M94673</link>
      <description>&lt;P&gt;one extra question , props.conf and transforms.conf are created  $SPLUNK_HOME/etc/deployment-apps/YOURAPP/local  or it can be created by GUI  &lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 15:06:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437508#M94673</guid>
      <dc:creator>lmjoin</dc:creator>
      <dc:date>2018-06-07T15:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: Spunk indexes.conf by deployment server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437509#M94674</link>
      <description>&lt;P&gt;You have to have the files manually added to deployment apps. You can however create on GUI and copy paste into deployment apps.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jun 2018 05:49:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437509#M94674</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2018-06-08T05:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: Spunk indexes.conf by deployment server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437510#M94675</link>
      <description>&lt;P&gt;how to create  props.conf and transforms.conf  by GUI , any idea , thanks in advance&lt;/P&gt;</description>
      <pubDate>Sat, 09 Jun 2018 10:03:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437510#M94675</guid>
      <dc:creator>lmjoin</dc:creator>
      <dc:date>2018-06-09T10:03:53Z</dc:date>
    </item>
    <item>
      <title>Re: Spunk indexes.conf by deployment server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437511#M94676</link>
      <description>&lt;P&gt;yeah, simply create a new data input and when you create it add a new sourcetype and configure it as needed. that will generate the files for you ^^&lt;/P&gt;</description>
      <pubDate>Sat, 09 Jun 2018 10:14:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437511#M94676</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2018-06-09T10:14:36Z</dc:date>
    </item>
    <item>
      <title>Re: Spunk indexes.conf by deployment server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437512#M94677</link>
      <description>&lt;P&gt;Thanks for reply ,&lt;/P&gt;

&lt;P&gt;I have put indexes.conf , props.conf and transforms.conf on  $SPLUNK_HOME/etc/deployment-apps/YOURAPP/local on deployment server and push , it showing successfully done not found no indexes.conf,props.conf and transforms.conf on indexer ( independent not in clustering ) . Please help me.&lt;BR /&gt;
Thanks&lt;BR /&gt;
Lalit&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2019 04:11:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexes-conf-by-deployment-server/m-p/437512#M94677</guid>
      <dc:creator>lmjoin</dc:creator>
      <dc:date>2019-02-11T04:11:14Z</dc:date>
    </item>
  </channel>
</rss>

