Splunk Search

Config consolidation

rhysjones
Path Finder

Hi Everyone,

Just throwing this one out there. Our install is a couple of years old and has gone through several upgrades and a server move. Over that time we have slowly learned more and more about how it all hangs together, mended our ways, and gradually improved things. We were struck with the 5.0 bug where we can;t use the GUI so I have been elbows deep in the config files doing it the real way. In doing so I was having a look at the various field extractions, saved searches, indexs, inputs, and so forth. Due to the way the WEB interface cleverly places settings in the config files of the app you were in at the time, the various configs are all over the place. Spread out over system local, apps, and users.

So the question, would it be sensible to go through and relocate all the config back into more appropriate config files (ie indexes and inputs in the system local, extractions in the app, and so forth) ? Or should I just leave well enough alone ?

Thanks in advance for any wise comments and advice.

Rhys

0 Karma

jmheaton
Path Finder

I'm actually sitting in the same boat here.
Been searching for a way to do this for a couple weeks.

I'm about to test merging configs onto a dev environment. I'll post back when i find something interesting.

0 Karma

rhysjones
Path Finder

Thanks and good luck. We did a bit of a cleanup in the end ourselves and it worked ok.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...