Getting Data In

Information on *.conf files

ppurokit
Path Finder

Hi All,

I have a very basic doubt with respect to all the *.conf files.

I have transforms.conf , props.conf and alert_actions.conf file in which I have some config written. But all these *.conf files are part of an App which i have created myself.

I know by default we can do all the changes and store it in ~splunk/etc/system/local.

But i want to do all the customizations and ship it as part of an App which i have developed and it should be global.

All your inputs are welcome.

0 Karma

kristian_kolb
Ultra Champion

This might be helpful (see "Make objects globally available")

http://docs.splunk.com/Documentation/Splunk/6.0/AdvancedDev/SetPermissions

/K

ppurokit
Path Finder

Thanks for he inputs. This really helped me.

So for adding alert_actions.conf in default.meta do i need to add like the below:

[alert_actions]
export = system

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...