Getting Data In

Inputs, Props and Transforms per App?

JensT
Communicator

Hello,

is it possible in Splunk 4.2.3+ to have separate Inputs, Props and Transforms per App?

Example:
App1: Listen on Port 10000, Extract Field foo1 only for the data from App1
App1: Listen on Port 20000, Extract Field foo2 only for the data from App2

Regards,

Jens

0 Karma

Ayn
Legend

Yes, these kinds of settings can be defined per app. You might want to have a look at this section of the docs: http://docs.splunk.com/Documentation/Splunk/latest/admin/Wheretofindtheconfigurationfiles

0 Karma

Ayn
Legend

Ah, I see I misunderstood your question. No, the configurations are indeed merged. It is not possible to separate that per app - you'd have to use different sources, sourcetypes or similar.

0 Karma

JensT
Communicator

Hi,

so you say the configurations are not merged? And settings from App1 are not applied to App2?

Jens

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...