Getting Data In

cluster configuration bundle files for sourcetype and index addition

dhavamanis
Builder

If we add new index and sourcetype, what are the files to be bundled in master to sync the clustered peer and search nodes. also please provide the location of the files to be copied from where to where.

0 Karma
1 Solution

ofrachon
Path Finder

As described in Splunk documentation, you should put your stuff in $SPLUNK_HOME/etc/master-apps/app1, $SPLUNK_HOME/etc/master-apps/app2 instead of $SPLUNK_HOME/etc/master-apps/_cluster

Everything about the configuration bundle can be found here :
http://docs.splunk.com/Documentation/Splunk/6.1.2/Indexer/Updatepeerconfigurations

View solution in original post

ofrachon
Path Finder

As described in Splunk documentation, you should put your stuff in $SPLUNK_HOME/etc/master-apps/app1, $SPLUNK_HOME/etc/master-apps/app2 instead of $SPLUNK_HOME/etc/master-apps/_cluster

Everything about the configuration bundle can be found here :
http://docs.splunk.com/Documentation/Splunk/6.1.2/Indexer/Updatepeerconfigurations

dhavamanis
Builder

We have copied the files from etc/system/local/ (props.conf and indexes.conf ) to etc/master-apps/_cluster/local/, The indexes and sourcetype are created in peer nodes after pushing from master node. But its not created in search head node. Can you please suggest.

0 Karma
Get Updates on the Splunk Community!

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...