Getting Data In

cluster configuration bundle files for sourcetype and index addition

dhavamanis
Builder

If we add new index and sourcetype, what are the files to be bundled in master to sync the clustered peer and search nodes. also please provide the location of the files to be copied from where to where.

0 Karma
1 Solution

ofrachon
Path Finder

As described in Splunk documentation, you should put your stuff in $SPLUNK_HOME/etc/master-apps/app1, $SPLUNK_HOME/etc/master-apps/app2 instead of $SPLUNK_HOME/etc/master-apps/_cluster

Everything about the configuration bundle can be found here :
http://docs.splunk.com/Documentation/Splunk/6.1.2/Indexer/Updatepeerconfigurations

View solution in original post

ofrachon
Path Finder

As described in Splunk documentation, you should put your stuff in $SPLUNK_HOME/etc/master-apps/app1, $SPLUNK_HOME/etc/master-apps/app2 instead of $SPLUNK_HOME/etc/master-apps/_cluster

Everything about the configuration bundle can be found here :
http://docs.splunk.com/Documentation/Splunk/6.1.2/Indexer/Updatepeerconfigurations

dhavamanis
Builder

We have copied the files from etc/system/local/ (props.conf and indexes.conf ) to etc/master-apps/_cluster/local/, The indexes and sourcetype are created in peer nodes after pushing from master node. But its not created in search head node. Can you please suggest.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...