<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Does Splunk ES live entirely within etc/apps? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Does-Splunk-ES-live-entirely-within-etc-apps/m-p/403364#M4628</link>
    <description>&lt;P&gt;Is there any component that makes Splunk ES tick, which isn't inside the directory etc/apps?&lt;/P&gt;</description>
    <pubDate>Mon, 25 Jun 2018 17:55:16 GMT</pubDate>
    <dc:creator>andrewaalin</dc:creator>
    <dc:date>2018-06-25T17:55:16Z</dc:date>
    <item>
      <title>Does Splunk ES live entirely within etc/apps?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Does-Splunk-ES-live-entirely-within-etc-apps/m-p/403364#M4628</link>
      <description>&lt;P&gt;Is there any component that makes Splunk ES tick, which isn't inside the directory etc/apps?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 17:55:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Does-Splunk-ES-live-entirely-within-etc-apps/m-p/403364#M4628</guid>
      <dc:creator>andrewaalin</dc:creator>
      <dc:date>2018-06-25T17:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk ES live entirely within etc/apps?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Does-Splunk-ES-live-entirely-within-etc-apps/m-p/403365#M4629</link>
      <description>&lt;P&gt;It depends on what you mean. Let me try to explain:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Short answer&lt;/STRONG&gt;&lt;BR /&gt;
ES is indeed composed of a series of apps. In that sense, it is indeed within etc/apps.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Long answer&lt;/STRONG&gt;&lt;BR /&gt;
There are some times in which ES creates files outside of etc/apps. Some examples include:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Log files are made in var/log/splunk&lt;/LI&gt;
&lt;LI&gt;Stash files are made in var/spool/splunk (stash files are created to send event&lt;/LI&gt;
&lt;LI&gt;Lookup editing involves creating temporary lookup files in a shared directory&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;It is also important to note that apps are sometimes placed outside of etc/apps (for example with apps are placed in the slave-apps directory on indexer clusters).&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 18:15:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Does-Splunk-ES-live-entirely-within-etc-apps/m-p/403365#M4629</guid>
      <dc:creator>LukeMurphey</dc:creator>
      <dc:date>2018-06-25T18:15:23Z</dc:date>
    </item>
  </channel>
</rss>

