Getting Data In

where to add my props.conf for new sourcetype - created using preview

Skins
Path Finder

I want to push out a props .conf file to monitor a file which resides on two machines with forwarders deployed.

my env consists of 1 x sh , 2 x indexer (not clustered) 2 x ufs

So far i have used the manual file upload method to create a new sourcetype and used the preview window to separate and timestamp my events how i want.

Now i'm unclear best practice to deploy these to the indexers and where they should reside ? should they also be added to my deployment apps directory and deployed to the forwarders ?

gratzi

Tags (1)
0 Karma

adonio
Ultra Champion

Hello @Skins,
There are couple questions here, I will try to address one by one
You will probably want to push inputs.conf to monitor a file and not props.conf,
this is a great wiki page that explains where conf files go:
https://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F
to automate this process across forwarder (and other splunk instances) you can use one of your splunk instances as a Deployment Server. According to your architecture description, your Search Head is the best candidate.
here is docs on how to configure deployment server and deployment clients (pay attention that Indexers can be clients too!):
http://docs.splunk.com/Documentation/Splunk/6.6.0/Updating/Configuredeploymentclients
now you can build small apps that will carry configurations such as inputs, outputs, props and more!
create serverclasses and assign clients and apps to groups, now you can control your Indexers configuration and forwarders configurations from one single machine.

Let us know if it worked well.

hope it helps

Skins
Path Finder

That was an error in my original post - i meant the inputs.conf for the file monitoring.

I didnt however think of using the DS to deploy to the indexers as well as the UF's

gratzi

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...