Getting Data In

monitoring for /root/.bash_history works for particular copies of inputs.conf (depending on directory structure)

heterodyned
Path Finder

Hello Folks,

I have two copies of inputs.conf, one is under the etc/apps/local directory ( created the local and placed inputs.conf) , now the inputs.conf in the apps directory is actually a copy of the inputs.conf from system/local with minor modifications and additional parameters, now I am tryin to monitor /root/.bash_history/. this monitor works fine if I place it under /etc/system/local/inputs.conf but if i place it inside /apps/local/ , it doesnt work fine, and the same holds true for few other fschange parameters like /home, /etc

any idea? I have placed the ownership for all these under splunk only ..

- Raghu

Tags (1)
0 Karma

heterodyned
Path Finder

This issue got resolved, i was going wrong in creating directory structure, the precedence follows the order of /etc/system/local & /etc/apps/ABCD/local ( i had this placed as /etc/apps/local)

Raghu

hexx
Splunk Employee
Splunk Employee

Absolutely. More detailed information about configuration file precedence can be found in the admin manual :
http://www.splunk.com/base/Documentation/4.1.4/Admin/Wheretofindtheconfigurationfiles

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...