Getting Data In

forwarder input and ouput conf priority

mpreddy
Communicator

i have an universal forwarder that has 2 apps . both the apps have their inputs and outputs. Both the apps are forwarding to 2 different indexers (like app1- idx1 app2-idx2). Suppose if i create an inputs.conf in an system level where it will forward?

what i understand is, File precedence in Splunk is:

System local directory: top priority
App local directories
App default directories
System default directory: lowest priority

So without outputs.conf define in system level which app will take an priority.

0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

You will need to understand full app context sorting priority also.. This is described in the document you copied from

To determine priority among the collection of apps directories, Splunk uses ASCII sort order. Files in an apps directory named "A" have a higher priority than files in an apps directory named "B", and so on. Also, all apps starting with an uppercase letter have precedence over any apps starting with a lowercase letter, due to ASCII sort order. ("A" has precedence over "Z", but "Z" has precedence over "a", for example.)

In addition, numbered directories have a higher priority than alphabetical directories and are evaluated in lexicographic, not numerical, order.

See doc file here : http://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Wheretofindtheconfigurationfiles#How_app_dir...

Additionally, you can have different outputs.conf, although this is against best practices. In these outputs you can specificy different output groups, and then in your inputs, direct these towards those specific output groups. This might be more along the lines of your question.

View solution in original post

pradeepkumarg
Influencer

Precedence order for inputs.conf and outputs.conf is independent of each other

Check below for detailed documentation

https://docs.splunk.com/Documentation/Splunk/6.5.1/Admin/Wheretofindtheconfigurationfiles

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

You will need to understand full app context sorting priority also.. This is described in the document you copied from

To determine priority among the collection of apps directories, Splunk uses ASCII sort order. Files in an apps directory named "A" have a higher priority than files in an apps directory named "B", and so on. Also, all apps starting with an uppercase letter have precedence over any apps starting with a lowercase letter, due to ASCII sort order. ("A" has precedence over "Z", but "Z" has precedence over "a", for example.)

In addition, numbered directories have a higher priority than alphabetical directories and are evaluated in lexicographic, not numerical, order.

See doc file here : http://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Wheretofindtheconfigurationfiles#How_app_dir...

Additionally, you can have different outputs.conf, although this is against best practices. In these outputs you can specificy different output groups, and then in your inputs, direct these towards those specific output groups. This might be more along the lines of your question.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...