<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Inputs Conf on Deployment Apps and HFs in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Inputs-Conf-on-Deployment-Apps-and-HFs/m-p/676152#M231287</link>
    <description>&lt;P&gt;Hi Splunkers,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have the following situation, and interested in another opinion:&lt;BR /&gt;&lt;BR /&gt;We have a distributed environment with clusters indexers and SHs, and HFs in distributed sites. We are using a deployer to push out CONFs to the HFs and other assets defined by serverclass. I am trying to set-up a configuration where the HFs are receiving data from a remote host inbound on a specific TCP port.&lt;/P&gt;&lt;P&gt;HF Deployment App:&lt;BR /&gt;local\inputs.conf&lt;BR /&gt;&lt;BR /&gt;in inputs.conf, there is a stanza for the expected data being input&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Remote Host 1
[tcp:12345]
index = indexA
sourcetype = sourceType1
disabled = 0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now there is a TA for this data type but it has an inputs.conf defined as:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[tcp://22245]
connection_host = dns
index = indexSomethingElse
sourcetype = sourceType
disabled = 0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which one takes precedence? And if the indexes are different, will this mess up the ingestion and indexing?&lt;BR /&gt;&lt;BR /&gt;Am I right in assuming that the inputs.conf defined for the overall inputs take precedence?&lt;BR /&gt;&lt;BR /&gt;REF:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.3/Admin/Wheretofindtheconfigurationfiles" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.3/Admin/Wheretofindtheconfigurationfiles&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 31 Jan 2024 18:40:24 GMT</pubDate>
    <dc:creator>JohnEGones</dc:creator>
    <dc:date>2024-01-31T18:40:24Z</dc:date>
    <item>
      <title>Inputs Conf on Deployment Apps and HFs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Inputs-Conf-on-Deployment-Apps-and-HFs/m-p/676152#M231287</link>
      <description>&lt;P&gt;Hi Splunkers,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have the following situation, and interested in another opinion:&lt;BR /&gt;&lt;BR /&gt;We have a distributed environment with clusters indexers and SHs, and HFs in distributed sites. We are using a deployer to push out CONFs to the HFs and other assets defined by serverclass. I am trying to set-up a configuration where the HFs are receiving data from a remote host inbound on a specific TCP port.&lt;/P&gt;&lt;P&gt;HF Deployment App:&lt;BR /&gt;local\inputs.conf&lt;BR /&gt;&lt;BR /&gt;in inputs.conf, there is a stanza for the expected data being input&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Remote Host 1
[tcp:12345]
index = indexA
sourcetype = sourceType1
disabled = 0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now there is a TA for this data type but it has an inputs.conf defined as:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[tcp://22245]
connection_host = dns
index = indexSomethingElse
sourcetype = sourceType
disabled = 0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which one takes precedence? And if the indexes are different, will this mess up the ingestion and indexing?&lt;BR /&gt;&lt;BR /&gt;Am I right in assuming that the inputs.conf defined for the overall inputs take precedence?&lt;BR /&gt;&lt;BR /&gt;REF:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.3/Admin/Wheretofindtheconfigurationfiles" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.3/Admin/Wheretofindtheconfigurationfiles&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2024 18:40:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Inputs-Conf-on-Deployment-Apps-and-HFs/m-p/676152#M231287</guid>
      <dc:creator>JohnEGones</dc:creator>
      <dc:date>2024-01-31T18:40:24Z</dc:date>
    </item>
    <item>
      <title>Re: Inputs Conf on Deployment Apps and HFs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Inputs-Conf-on-Deployment-Apps-and-HFs/m-p/676163#M231288</link>
      <description>&lt;P&gt;Depends on whether within the TA the conf is in the local or default&amp;nbsp; directory. If it's in local, it depends on the alphabetical order of apps. Read the document once again. And do a btool --debug to verify.&lt;/P&gt;&lt;P&gt;Also you're &lt;EM&gt;not&lt;/EM&gt; using deployer to distribute apps to HFs. You're using delpyment server for it. Deployer is for search head cluster.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2024 19:17:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Inputs-Conf-on-Deployment-Apps-and-HFs/m-p/676163#M231288</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-01-31T19:17:11Z</dc:date>
    </item>
  </channel>
</rss>

