Getting Data In

Combining input.conf files for the same app in different data centers

damonmanni
Path Finder

Currently I deploy an app for Oracle log files on servers located in DC1 as such:
deploy svr> /opt/splunk/etc/deployment-apps/dc1_oracledb_inputs

And then I also deploy an app for Oracle log files on servres located in DC2 as such:
deploy svr> /opt/splunk/etc/deployment-apps/dc2_oracledb_inputs

This now means that I have 2 specific stanza's in my serverclass.conf file whitelisting specific servers found in that DC of choice as such:
[serverClass:dc1_oracledb]
whitelist.0 = mdc1dpm001
[serverClass:dc1_oracledb:app:dc1_oracledb_inputs]

[serverClass:dc2_oracledb]
whitelist.0 = mdc2dpm001
[serverClass:dc2_oracledb:app:dc2_oracledb_inputs]

My question is:
can I combine these 2 stanzas into 1 stanza with the new inputs.conf now containing both log file path entries found from each - as some of the log file paths will only exist/are relative on certain svrs related to their DCx/physical location?

I though that if I combine the entries from each individual inputs.conf into 1 inputs.conf - does Splunk look thru the new inputs.conf, and ignore any dir paths that are not found on the client? Or will the above idea cause unnecessary overhead on splunkd thus affecting performance?

Currently it is time consuming to create/manage yet another deployment app based on only a few small diffs from another similar app inputs.conf file.

Apologies in advance, if my question is not clear.

cheers,
Damon

Tags (2)
0 Karma

woodcock
Esteemed Legend

This will be fine and not cause any problem or overhead for Splunk. It will take a trivial effort for Splunk to determine that the directory does not exist on the server so don't worry about that.

0 Karma

kristian_kolb
Ultra Champion

I should say that it is probably not a problem to send out the same inputs.conf based on a small difference in the amount of files being monitored. Just ensure that sourcetype and index are the same for hosts in the different DCs (as that is something that is good to put in inputs.conf).

Perhaps if you posted the actual inputs.conf files you could get better help.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...

Keep the Learning Going with the New Best of .conf Hub

Hello Splunkers, With .conf26 getting closer, there’s already a lot of excitement building around this year’s ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...