Getting Data In

Nullque setup help

Antioch
Path Finder

basically I am attempting to filter wmi eventlogs before they are indexed by the splunk server, I found a topic about this but I had a few more basic questions. I'm looking at the steps for setting up forwarding to the nullque here: http://docs.splunk.com/Documentation/Splunk/5.0.3/Deploy/Routeandfilterdatad but im not quite understanding the directions. First step is to edit props.conf, but when I look in my directory I have multiple props.conf files. Do I need to edit all of them? If not what is the path of the file I should be editing? I found the props.conf under splunkdir/etc/system/default, is this the right one? if so this file indicated it should be placed in the etc/system/local file, should I just be copying and pasting the whole file? or just the relevant sections? same goes for the transforms.conf, which one is the correct one? thanks for the help everyone

Tags (1)
0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

No you do not need to edit all of the files. Please look at this link below in the docs for file precedence. In most cases you'll create a new file under /system/local for props.conf and transforms.conf but it really depends. As long as you are not changing the default directory you are ok, since that is really for the base system or application. Changes within 'local' won't be overridden when you upgrade versions of Splunk.

http://docs.splunk.com/Documentation/Splunk/5.0.3/Admin/Wheretofindtheconfigurationfiles

View solution in original post

sdaniels
Splunk Employee
Splunk Employee

No you do not need to edit all of the files. Please look at this link below in the docs for file precedence. In most cases you'll create a new file under /system/local for props.conf and transforms.conf but it really depends. As long as you are not changing the default directory you are ok, since that is really for the base system or application. Changes within 'local' won't be overridden when you upgrade versions of Splunk.

http://docs.splunk.com/Documentation/Splunk/5.0.3/Admin/Wheretofindtheconfigurationfiles

softunlockiphon
New Member

good idea for all very nice hehehehe

0 Karma

Antioch
Path Finder

Thank you, the routing setup page should have a link back to this doc for reference.

0 Karma
Get Updates on the Splunk Community!

Dashboard Studio Challenge - Learn New Tricks, Showcase Your Skills, and Win Prizes!

Reimagine what you can do with your dashboards. Dashboard Studio is Splunk’s newest dashboard builder to ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...