Getting Data In

forwarder input and ouput conf priority

mpreddy
Communicator

i have an universal forwarder that has 2 apps . both the apps have their inputs and outputs. Both the apps are forwarding to 2 different indexers (like app1- idx1 app2-idx2). Suppose if i create an inputs.conf in an system level where it will forward?

what i understand is, File precedence in Splunk is:

System local directory: top priority
App local directories
App default directories
System default directory: lowest priority

So without outputs.conf define in system level which app will take an priority.

0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

You will need to understand full app context sorting priority also.. This is described in the document you copied from

To determine priority among the collection of apps directories, Splunk uses ASCII sort order. Files in an apps directory named "A" have a higher priority than files in an apps directory named "B", and so on. Also, all apps starting with an uppercase letter have precedence over any apps starting with a lowercase letter, due to ASCII sort order. ("A" has precedence over "Z", but "Z" has precedence over "a", for example.)

In addition, numbered directories have a higher priority than alphabetical directories and are evaluated in lexicographic, not numerical, order.

See doc file here : http://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Wheretofindtheconfigurationfiles#How_app_dir...

Additionally, you can have different outputs.conf, although this is against best practices. In these outputs you can specificy different output groups, and then in your inputs, direct these towards those specific output groups. This might be more along the lines of your question.

View solution in original post

pradeepkumarg
Influencer

Precedence order for inputs.conf and outputs.conf is independent of each other

Check below for detailed documentation

https://docs.splunk.com/Documentation/Splunk/6.5.1/Admin/Wheretofindtheconfigurationfiles

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

You will need to understand full app context sorting priority also.. This is described in the document you copied from

To determine priority among the collection of apps directories, Splunk uses ASCII sort order. Files in an apps directory named "A" have a higher priority than files in an apps directory named "B", and so on. Also, all apps starting with an uppercase letter have precedence over any apps starting with a lowercase letter, due to ASCII sort order. ("A" has precedence over "Z", but "Z" has precedence over "a", for example.)

In addition, numbered directories have a higher priority than alphabetical directories and are evaluated in lexicographic, not numerical, order.

See doc file here : http://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Wheretofindtheconfigurationfiles#How_app_dir...

Additionally, you can have different outputs.conf, although this is against best practices. In these outputs you can specificy different output groups, and then in your inputs, direct these towards those specific output groups. This might be more along the lines of your question.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...