Deployment Architecture

event filtering and deployment server

jambajuice
Communicator

If I have a UDP input defined in /etc/system/local/inputs.conf and I create event filters using a transforms.conf and props.conf files that are located in /etc/apps/search/local, will those filters be applied to the UDP input even though the input is defined elsewhere?

When will variables be supported by the inputs.conf file? We need to tag various inputs with a unique identifier in hundreds of our stores. Currently we can't use the deployment server to manage those inputs because it overwrites the inputs.conf file every time a change is made, thus erasing the unique tag for the input.

Thx.

Craig

Tags (2)

gkanapathy
Splunk Employee
Splunk Employee

Yes, inputs and index-time transforms are applied to a single global context, regardless of what file they are configured in. (Search-time extractions have more complex scope rules.)

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...