Getting Data In

Splunk Cloud - How to change props.conf, transforms.conf, and index.conf?

New Member

Hi,
I am on trial version of Splunk cloud where we are provided just with the splunk endpoint.

In Splunk Enterprise Trial on AWS marketplace, we actually can SSH into the machine and change props.conf etc

How can we achieve the same on Splunk Cloud?

0 Karma
1 Solution

Esteemed Legend

You can edit all of that stuff (although not every possible option) from the GUI and that is what you must do. There ABSOLUTELY NO CLI for Splunk Cloud. This is one of the reasons that I never recommend Splunk Cloud; almost everybody would be better of recreating the same architecture in AWS under your own control. You can hare PS like Splunxter to do this kind of thing if you need help.

View solution in original post

0 Karma

Esteemed Legend

You can edit all of that stuff (although not every possible option) from the GUI and that is what you must do. There ABSOLUTELY NO CLI for Splunk Cloud. This is one of the reasons that I never recommend Splunk Cloud; almost everybody would be better of recreating the same architecture in AWS under your own control. You can hare PS like Splunxter to do this kind of thing if you need help.

View solution in original post

0 Karma