Getting Data In

Nullque setup help

Antioch
Path Finder

basically I am attempting to filter wmi eventlogs before they are indexed by the splunk server, I found a topic about this but I had a few more basic questions. I'm looking at the steps for setting up forwarding to the nullque here: http://docs.splunk.com/Documentation/Splunk/5.0.3/Deploy/Routeandfilterdatad but im not quite understanding the directions. First step is to edit props.conf, but when I look in my directory I have multiple props.conf files. Do I need to edit all of them? If not what is the path of the file I should be editing? I found the props.conf under splunkdir/etc/system/default, is this the right one? if so this file indicated it should be placed in the etc/system/local file, should I just be copying and pasting the whole file? or just the relevant sections? same goes for the transforms.conf, which one is the correct one? thanks for the help everyone

Tags (1)
0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

No you do not need to edit all of the files. Please look at this link below in the docs for file precedence. In most cases you'll create a new file under /system/local for props.conf and transforms.conf but it really depends. As long as you are not changing the default directory you are ok, since that is really for the base system or application. Changes within 'local' won't be overridden when you upgrade versions of Splunk.

http://docs.splunk.com/Documentation/Splunk/5.0.3/Admin/Wheretofindtheconfigurationfiles

View solution in original post

sdaniels
Splunk Employee
Splunk Employee

No you do not need to edit all of the files. Please look at this link below in the docs for file precedence. In most cases you'll create a new file under /system/local for props.conf and transforms.conf but it really depends. As long as you are not changing the default directory you are ok, since that is really for the base system or application. Changes within 'local' won't be overridden when you upgrade versions of Splunk.

http://docs.splunk.com/Documentation/Splunk/5.0.3/Admin/Wheretofindtheconfigurationfiles

softunlockiphon
New Member

good idea for all very nice hehehehe

0 Karma

Antioch
Path Finder

Thank you, the routing setup page should have a link back to this doc for reference.

0 Karma
Get Updates on the Splunk Community!

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Automatic Discovery Part 2: Setup and Best Practices

In Part 1 of this series, we covered what Automatic Discovery is and why it’s critical for observability at ...