Getting Data In

cluster configuration bundle files for sourcetype and index addition

dhavamanis
Builder

If we add new index and sourcetype, what are the files to be bundled in master to sync the clustered peer and search nodes. also please provide the location of the files to be copied from where to where.

0 Karma
1 Solution

ofrachon
Path Finder

As described in Splunk documentation, you should put your stuff in $SPLUNK_HOME/etc/master-apps/app1, $SPLUNK_HOME/etc/master-apps/app2 instead of $SPLUNK_HOME/etc/master-apps/_cluster

Everything about the configuration bundle can be found here :
http://docs.splunk.com/Documentation/Splunk/6.1.2/Indexer/Updatepeerconfigurations

View solution in original post

ofrachon
Path Finder

As described in Splunk documentation, you should put your stuff in $SPLUNK_HOME/etc/master-apps/app1, $SPLUNK_HOME/etc/master-apps/app2 instead of $SPLUNK_HOME/etc/master-apps/_cluster

Everything about the configuration bundle can be found here :
http://docs.splunk.com/Documentation/Splunk/6.1.2/Indexer/Updatepeerconfigurations

dhavamanis
Builder

We have copied the files from etc/system/local/ (props.conf and indexes.conf ) to etc/master-apps/_cluster/local/, The indexes and sourcetype are created in peer nodes after pushing from master node. But its not created in search head node. Can you please suggest.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...