I am in /opt/apps/splunk/etc/apps/search/default
when I edit commands.conf it says
DO NOT EDIT THIS FILE!
does that mean I should make a new commands.conf with my new command and place in /opt/apps/splunk/etc/apps/search/local ?
thanks
You could make changes to a file in /etc/apps/search/default/and they would work, until you upgraded. The reason you're instructed to make changes in /local is that those changes are preserved on upgrade. So yes, you should either copy, or make a new file called commands.conf in $SPLUNK_HOME/etc/apps/search/local for your new command.
You could make changes to a file in /etc/apps/search/default/and they would work, until you upgraded. The reason you're instructed to make changes in /local is that those changes are preserved on upgrade. So yes, you should either copy, or make a new file called commands.conf in $SPLUNK_HOME/etc/apps/search/local for your new command.