Deployment Architecture

Custom conf files replication in search head cluster

VatsalJagani
SplunkTrust
SplunkTrust

I've one App which has Add-on builder created configuration page with API key, proxy settings, etc. This configuration is going to store in _settings.conf in local.

If I configure this on one of the search head, will this configuration replicates to other search heads?
If Yes - Any document that can say that custom conf files replicates to other search heads.
If No - How should I configure App?

1 Solution

esix_splunk
Splunk Employee
Splunk Employee

Yes custom configuration files will be replicated, within some boundaries..

PLease read this doc file : https://docs.splunk.com/Documentation/Splunk/7.2.6/DistSearch/HowconfrepoworksinSHC

This outlines what is replicated, and what triggers that replication.

View solution in original post

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Yes custom configuration files will be replicated, within some boundaries..

PLease read this doc file : https://docs.splunk.com/Documentation/Splunk/7.2.6/DistSearch/HowconfrepoworksinSHC

This outlines what is replicated, and what triggers that replication.

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@esix_splunk - I want to add here that, if Addon/App is making all conf changes through RestAPI then only it will replicate, if it is making change with ConfParser then it will not replicate.

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Note this, as stated in the docs..

The cluster replicates changes made through these methods:

Splunk Web
The Splunk CLI
The REST API

So yes, using a custom python command to modify configurations will not trigger a configuration update. If you're editing this way, it would be better to finalize the script with a hit against the rest config endpoint for the app....

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Brett Adams

In our third Spotlight feature, we're excited to shine a light on Brett—a Splunk consultant, innovative ...

Index This | What can you do to make 55,555 equal 500?

April 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...