Getting Data In

where to add my props.conf for new sourcetype - created using preview

Skins
Path Finder

I want to push out a props .conf file to monitor a file which resides on two machines with forwarders deployed.

my env consists of 1 x sh , 2 x indexer (not clustered) 2 x ufs

So far i have used the manual file upload method to create a new sourcetype and used the preview window to separate and timestamp my events how i want.

Now i'm unclear best practice to deploy these to the indexers and where they should reside ? should they also be added to my deployment apps directory and deployed to the forwarders ?

gratzi

Tags (1)
0 Karma

adonio
Ultra Champion

Hello @Skins,
There are couple questions here, I will try to address one by one
You will probably want to push inputs.conf to monitor a file and not props.conf,
this is a great wiki page that explains where conf files go:
https://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F
to automate this process across forwarder (and other splunk instances) you can use one of your splunk instances as a Deployment Server. According to your architecture description, your Search Head is the best candidate.
here is docs on how to configure deployment server and deployment clients (pay attention that Indexers can be clients too!):
http://docs.splunk.com/Documentation/Splunk/6.6.0/Updating/Configuredeploymentclients
now you can build small apps that will carry configurations such as inputs, outputs, props and more!
create serverclasses and assign clients and apps to groups, now you can control your Indexers configuration and forwarders configurations from one single machine.

Let us know if it worked well.

hope it helps

Skins
Path Finder

That was an error in my original post - i meant the inputs.conf for the file monitoring.

I didnt however think of using the DS to deploy to the indexers as well as the UF's

gratzi

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...