Deployment Architecture

Is there a simple way to get all config files from $SPLUNK_HOME/etc?

danielbb
Motivator

A fellow here would like to compare the config files across a cluster of three SHs. So, what's an easy way to get all the config files under $SPLUNK_HOME/etc?

We thought about getting the diags from these three, or run the btool for each config file. Is there a way to get all the config files via a nice Unix command?

0 Karma
1 Solution

MuS
Legend

Hi danielbb,

Sadly there is no single show them all command in Splunk but have a look at this answer https://answers.splunk.com/answers/293407/how-do-i-show-the-running-configuration-on-my-forw.html#an... it will show an example to list all Splunk .conf files.
With the output you can compare it server by server.

Hope this helps ...

cheers, MuS

View solution in original post

bcusick_splunk
Splunk Employee
Splunk Employee

Hi Daniel - try this on for size:

find /opt/splunk/etc/ -type f -name '*.conf' | grep -v README | awk -F/ '{print $NF}' | awk -F\. '{print $1}' | sort -u > btool_list.txt; for i in $(cat btool_list.txt); do splunk btool $i list; done > complete_btool_output.txt

danielbb
Motivator

Worked perfectly fine - thank you.

0 Karma

MuS
Legend

Hi danielbb,

Sadly there is no single show them all command in Splunk but have a look at this answer https://answers.splunk.com/answers/293407/how-do-i-show-the-running-configuration-on-my-forw.html#an... it will show an example to list all Splunk .conf files.
With the output you can compare it server by server.

Hope this helps ...

cheers, MuS

danielbb
Motivator

@MuS, it's great but find /opt/apps/splunk/etc | grep .conf | grep -v README | awk -F/ '{ print $NF }' seems to need some improvements ... on one server find /opt/apps/splunk/etc | grep .conf | grep -v README | awk -F/ '{ print $NF }' | wc -l returns 3339 files...

0 Karma

MuS
Legend

If you improve the find you might end up missing some files but feel free to modify the find in anyway that works better for you 🙂

cheers, MuS

0 Karma

danielbb
Motivator

Ok - will do... : )

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...