In order to take a backup of the config files, I have copied a file to, let's say,
Will Splunk read the settings from the above file? I am assuming that it will not.
But why am I getting following error message in the internal logs?
ERROR Archiver - Failed to open file="/opt/splunk/etc/system/local/authorize.conf_bak_03_21_2018": Permission denied
What is the best way to backup the config files and save them in the same folder?
try to go for something like this:
authorize.bak inputs.bak outputs.bak props.bak transforms.bak
If you want to include the backup date, you could also create a folder with the date as its name.
I normally create a
/opt/splunk/etc/system/local/bckup folder and place the backup files there. The error you see gives another reason not to place the backup files in the same directory.