Getting Data In

cluster configuration bundle files for sourcetype and index addition

dhavamanis
Builder

If we add new index and sourcetype, what are the files to be bundled in master to sync the clustered peer and search nodes. also please provide the location of the files to be copied from where to where.

0 Karma
1 Solution

ofrachon
Path Finder

As described in Splunk documentation, you should put your stuff in $SPLUNK_HOME/etc/master-apps/app1, $SPLUNK_HOME/etc/master-apps/app2 instead of $SPLUNK_HOME/etc/master-apps/_cluster

Everything about the configuration bundle can be found here :
http://docs.splunk.com/Documentation/Splunk/6.1.2/Indexer/Updatepeerconfigurations

View solution in original post

ofrachon
Path Finder

As described in Splunk documentation, you should put your stuff in $SPLUNK_HOME/etc/master-apps/app1, $SPLUNK_HOME/etc/master-apps/app2 instead of $SPLUNK_HOME/etc/master-apps/_cluster

Everything about the configuration bundle can be found here :
http://docs.splunk.com/Documentation/Splunk/6.1.2/Indexer/Updatepeerconfigurations

dhavamanis
Builder

We have copied the files from etc/system/local/ (props.conf and indexes.conf ) to etc/master-apps/_cluster/local/, The indexes and sourcetype are created in peer nodes after pushing from master node. But its not created in search head node. Can you please suggest.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...