Getting Data In

Inputs, Props and Transforms per App?

JensT
Communicator

Hello,

is it possible in Splunk 4.2.3+ to have separate Inputs, Props and Transforms per App?

Example:
App1: Listen on Port 10000, Extract Field foo1 only for the data from App1
App1: Listen on Port 20000, Extract Field foo2 only for the data from App2

Regards,

Jens

0 Karma

Ayn
Legend

Yes, these kinds of settings can be defined per app. You might want to have a look at this section of the docs: http://docs.splunk.com/Documentation/Splunk/latest/admin/Wheretofindtheconfigurationfiles

0 Karma

Ayn
Legend

Ah, I see I misunderstood your question. No, the configurations are indeed merged. It is not possible to separate that per app - you'd have to use different sources, sourcetypes or similar.

0 Karma

JensT
Communicator

Hi,

so you say the configurations are not merged? And settings from App1 are not applied to App2?

Jens

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Supercharging Windows Security Detection Performance: Introducing Hybrid Field ...

Windows event logs—from Security auditing and Sysmon to PowerShell script blocks—form the operational backbone ...

Ditch the Manual Grind: Building AI Agents with Splunk

Ditch the Manual Grind: Building AI Agents with Splunk Let’s be real: your team’s time is being eaten alive. ...

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...