Dashboards & Visualizations

Are "default" and "local" folders case-sensitive in Splunk?

mgaraventa_splu
Splunk Employee
Splunk Employee

Hi all,

I've created my personal app with the default and local folders in them. I've realized that the conf files inside my local folder inside the app are not applied. I have named it "Local". Is there any issue by using uppercases when creating default and local folders? Thanks in advance for the answer.

Tags (3)
1 Solution

mgaraventa_splu
Splunk Employee
Splunk Employee

That's correct. "default" and "local" folders have to be all lowercases in Splunk. Otherwise their content will not be applied.

In general if you have doubts about conf files being applied, it's always a good idea to use the btool command to do the first troubleshooting in order to figure out if Splunk is missing or is doing anything wrong, for example because of a typo. See also the official btool documentation article for further details:

http://docs.splunk.com/Documentation/Splunk/6.0.1/Troubleshooting/Usebtooltotroubleshootconfiguratio...

View solution in original post

mgaraventa_splu
Splunk Employee
Splunk Employee

That's correct. "default" and "local" folders have to be all lowercases in Splunk. Otherwise their content will not be applied.

In general if you have doubts about conf files being applied, it's always a good idea to use the btool command to do the first troubleshooting in order to figure out if Splunk is missing or is doing anything wrong, for example because of a typo. See also the official btool documentation article for further details:

http://docs.splunk.com/Documentation/Splunk/6.0.1/Troubleshooting/Usebtooltotroubleshootconfiguratio...

Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...