Getting Data In

Nullque setup help

Antioch
Path Finder

basically I am attempting to filter wmi eventlogs before they are indexed by the splunk server, I found a topic about this but I had a few more basic questions. I'm looking at the steps for setting up forwarding to the nullque here: http://docs.splunk.com/Documentation/Splunk/5.0.3/Deploy/Routeandfilterdatad but im not quite understanding the directions. First step is to edit props.conf, but when I look in my directory I have multiple props.conf files. Do I need to edit all of them? If not what is the path of the file I should be editing? I found the props.conf under splunkdir/etc/system/default, is this the right one? if so this file indicated it should be placed in the etc/system/local file, should I just be copying and pasting the whole file? or just the relevant sections? same goes for the transforms.conf, which one is the correct one? thanks for the help everyone

Tags (1)
0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

No you do not need to edit all of the files. Please look at this link below in the docs for file precedence. In most cases you'll create a new file under /system/local for props.conf and transforms.conf but it really depends. As long as you are not changing the default directory you are ok, since that is really for the base system or application. Changes within 'local' won't be overridden when you upgrade versions of Splunk.

http://docs.splunk.com/Documentation/Splunk/5.0.3/Admin/Wheretofindtheconfigurationfiles

View solution in original post

sdaniels
Splunk Employee
Splunk Employee

No you do not need to edit all of the files. Please look at this link below in the docs for file precedence. In most cases you'll create a new file under /system/local for props.conf and transforms.conf but it really depends. As long as you are not changing the default directory you are ok, since that is really for the base system or application. Changes within 'local' won't be overridden when you upgrade versions of Splunk.

http://docs.splunk.com/Documentation/Splunk/5.0.3/Admin/Wheretofindtheconfigurationfiles

softunlockiphon
New Member

good idea for all very nice hehehehe

0 Karma

Antioch
Path Finder

Thank you, the routing setup page should have a link back to this doc for reference.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...