Splunk Search

Configuration stanza precedence vs Configuration file location precedence?

ankithreddy777
Contributor

For props.conf which has highest precedence.

In documentation, they said
[source::] settings override both [host::] and [] settings

1) if props.conf is in ..etc/system/local

[sourcetype1]
TIME_FORMAT=.....

...

2) And props.conf in etc/apps/app1/local/
[source::....]
TIME_FORMAT=.....

...

we know system/local has higher priority than app1/local.... But has high priority over

Could you please let me know which TIME_FORMAT setting will be applied,.
from system/local? OR App1/local?

Conf. file location precedence is higher OR stanza type precedence is higher?

0 Karma

adonio
Ultra Champion

system/local takes precedence
however, you are looking at different stanzas, iirc sourcetype akes precedence over host and source
read here all the way:
http://docs.splunk.com/Documentation/Splunk/7.1.2/Admin/Wheretofindtheconfigurationfiles

0 Karma

ankithreddy777
Contributor

Hi Adonia,

I am looking at different stanzas at different locations.

we know system/local has higher priority than app1/local.... But source has high priority over sourcetype.

Does source settings will be applied even though place at low precedence location.

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...