Deployment Architecture

Is there a simple way to get all config files from $SPLUNK_HOME/etc?

danielbb
Motivator

A fellow here would like to compare the config files across a cluster of three SHs. So, what's an easy way to get all the config files under $SPLUNK_HOME/etc?

We thought about getting the diags from these three, or run the btool for each config file. Is there a way to get all the config files via a nice Unix command?

0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi danielbb,

Sadly there is no single show them all command in Splunk but have a look at this answer https://answers.splunk.com/answers/293407/how-do-i-show-the-running-configuration-on-my-forw.html#an... it will show an example to list all Splunk .conf files.
With the output you can compare it server by server.

Hope this helps ...

cheers, MuS

View solution in original post

bcusick_splunk
Splunk Employee
Splunk Employee

Hi Daniel - try this on for size:

find /opt/splunk/etc/ -type f -name '*.conf' | grep -v README | awk -F/ '{print $NF}' | awk -F\. '{print $1}' | sort -u > btool_list.txt; for i in $(cat btool_list.txt); do splunk btool $i list; done > complete_btool_output.txt

danielbb
Motivator

Worked perfectly fine - thank you.

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi danielbb,

Sadly there is no single show them all command in Splunk but have a look at this answer https://answers.splunk.com/answers/293407/how-do-i-show-the-running-configuration-on-my-forw.html#an... it will show an example to list all Splunk .conf files.
With the output you can compare it server by server.

Hope this helps ...

cheers, MuS

danielbb
Motivator

@MuS, it's great but find /opt/apps/splunk/etc | grep .conf | grep -v README | awk -F/ '{ print $NF }' seems to need some improvements ... on one server find /opt/apps/splunk/etc | grep .conf | grep -v README | awk -F/ '{ print $NF }' | wc -l returns 3339 files...

0 Karma

MuS
SplunkTrust
SplunkTrust

If you improve the find you might end up missing some files but feel free to modify the find in anyway that works better for you 🙂

cheers, MuS

0 Karma

danielbb
Motivator

Ok - will do... : )

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...