Deployment Architecture

Is there a simple way to get all config files from $SPLUNK_HOME/etc?

danielbb
Motivator

A fellow here would like to compare the config files across a cluster of three SHs. So, what's an easy way to get all the config files under $SPLUNK_HOME/etc?

We thought about getting the diags from these three, or run the btool for each config file. Is there a way to get all the config files via a nice Unix command?

0 Karma
1 Solution

MuS
Legend

Hi danielbb,

Sadly there is no single show them all command in Splunk but have a look at this answer https://answers.splunk.com/answers/293407/how-do-i-show-the-running-configuration-on-my-forw.html#an... it will show an example to list all Splunk .conf files.
With the output you can compare it server by server.

Hope this helps ...

cheers, MuS

View solution in original post

bcusick_splunk
Splunk Employee
Splunk Employee

Hi Daniel - try this on for size:

find /opt/splunk/etc/ -type f -name '*.conf' | grep -v README | awk -F/ '{print $NF}' | awk -F\. '{print $1}' | sort -u > btool_list.txt; for i in $(cat btool_list.txt); do splunk btool $i list; done > complete_btool_output.txt

danielbb
Motivator

Worked perfectly fine - thank you.

0 Karma

MuS
Legend

Hi danielbb,

Sadly there is no single show them all command in Splunk but have a look at this answer https://answers.splunk.com/answers/293407/how-do-i-show-the-running-configuration-on-my-forw.html#an... it will show an example to list all Splunk .conf files.
With the output you can compare it server by server.

Hope this helps ...

cheers, MuS

danielbb
Motivator

@MuS, it's great but find /opt/apps/splunk/etc | grep .conf | grep -v README | awk -F/ '{ print $NF }' seems to need some improvements ... on one server find /opt/apps/splunk/etc | grep .conf | grep -v README | awk -F/ '{ print $NF }' | wc -l returns 3339 files...

0 Karma

MuS
Legend

If you improve the find you might end up missing some files but feel free to modify the find in anyway that works better for you 🙂

cheers, MuS

0 Karma

danielbb
Motivator

Ok - will do... : )

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...