Deployment Architecture

Which configuration file matters where in a distributed Splunk installation?

mghocke
Path Finder

Hi everybody,

I am trying to gain understanding on what configuration file matters to be where in a Splunk installation. I have a search head cluster, an indexer cluster, tons of universal forwarders, and a handful of heavy forwarders. Of the almost 60 .conf files in 6.5.x where do each of these have to be located? Search head, indexer, and/or forwarder? I am asking this question from a developer point of view in order to get the instructions right and also to understand the installation better. Is there some documentation on this out there?

Thanks!

--- Michael

0 Karma
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

That is a loaded question. Fully documented here: https://docs.splunk.com/Documentation/Splunk/latest/Admin/Aboutconfigurationfiles . I'm not sure what you mean by developer point of view, do you refer to Splunk App Development? There are more common files that are in use, not all of them need used in most instances. There are also conditions on when each file might go to a different Splunk instance. I highly recommend you take the Free Splunk Fundamentals (https://www.splunk.com/view/SP-CAAAPX9) course for a base understanding of what Splunk is and how it works at a higher level.

View solution in original post

ddrillic
Ultra Champion

From my perceptive, applying changes to the universal forwarders, is the most time consuming part of my work. The serverclass.conf is the sacred file ; -)

Deploy apps to clients

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

That is a loaded question. Fully documented here: https://docs.splunk.com/Documentation/Splunk/latest/Admin/Aboutconfigurationfiles . I'm not sure what you mean by developer point of view, do you refer to Splunk App Development? There are more common files that are in use, not all of them need used in most instances. There are also conditions on when each file might go to a different Splunk instance. I highly recommend you take the Free Splunk Fundamentals (https://www.splunk.com/view/SP-CAAAPX9) course for a base understanding of what Splunk is and how it works at a higher level.

mghocke
Path Finder

Thank you so much for answering. I think I found the page in the documentation that is relevant to my question: https://docs.splunk.com/Documentation/Splunk/6.6.1/Admin/Configurationparametersandthedatapipeline

I just wanted to know which parts of the configuration is needed on what tier of Splunk. I have a multi-tenancy setup and there are a few apps and add-ons that I need to modify in order to make sure they don't step on everybody's feet. So, I go through them and understand what they do and how they do it and modify them by, sometimes, erasing certain configuration files that are not needed on that specific tier. For example, I don't need an indexes.conf file on a search head nor do I usually need inputs.conf on an indexer. Some files, like props.conf and transforms.conf are needed everywhere because they do search-time or index-time transformations and extractions.

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...