Getting Data In

cluster configuration bundle files for sourcetype and index addition

dhavamanis
Builder

If we add new index and sourcetype, what are the files to be bundled in master to sync the clustered peer and search nodes. also please provide the location of the files to be copied from where to where.

0 Karma
1 Solution

ofrachon
Path Finder

As described in Splunk documentation, you should put your stuff in $SPLUNK_HOME/etc/master-apps/app1, $SPLUNK_HOME/etc/master-apps/app2 instead of $SPLUNK_HOME/etc/master-apps/_cluster

Everything about the configuration bundle can be found here :
http://docs.splunk.com/Documentation/Splunk/6.1.2/Indexer/Updatepeerconfigurations

View solution in original post

ofrachon
Path Finder

As described in Splunk documentation, you should put your stuff in $SPLUNK_HOME/etc/master-apps/app1, $SPLUNK_HOME/etc/master-apps/app2 instead of $SPLUNK_HOME/etc/master-apps/_cluster

Everything about the configuration bundle can be found here :
http://docs.splunk.com/Documentation/Splunk/6.1.2/Indexer/Updatepeerconfigurations

dhavamanis
Builder

We have copied the files from etc/system/local/ (props.conf and indexes.conf ) to etc/master-apps/_cluster/local/, The indexes and sourcetype are created in peer nodes after pushing from master node. But its not created in search head node. Can you please suggest.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...