Hi,
I'm wondering how Splunk (4.3.x) deals with new roles created through the GUI. Since they're located in etc/system, I suppose you have to distribute any changes by yourself, or is there a way to automate this?
That is how we handle authorize.conf. We have the common (shareable) information in a "splunk_system" app and the server specific information in $SPLUNK_HOME/etc/system/local. We do this for all the $SPLUNK_HOME/etc/system/local config files.
Maybe I should've searched better, but hopefully the link to the doc is useful to you. 🙂
I'm in a similar situation, but on 5.0.1. I'd love to see the solution as well.