Splunk Search

Inputs Conf on Deployment Apps and HFs

JohnEGones
Communicator

Hi Splunkers, 

Have the following situation, and interested in another opinion:

We have a distributed environment with clusters indexers and SHs, and HFs in distributed sites. We are using a deployer to push out CONFs to the HFs and other assets defined by serverclass. I am trying to set-up a configuration where the HFs are receiving data from a remote host inbound on a specific TCP port.

HF Deployment App:
local\inputs.conf

in inputs.conf, there is a stanza for the expected data being input

 

 

Remote Host 1
[tcp:12345]
index = indexA
sourcetype = sourceType1
disabled = 0

 

 

 

Now there is a TA for this data type but it has an inputs.conf defined as:

 

 

[tcp://22245]
connection_host = dns
index = indexSomethingElse
sourcetype = sourceType
disabled = 0

 

 

 

Which one takes precedence? And if the indexes are different, will this mess up the ingestion and indexing?

Am I right in assuming that the inputs.conf defined for the overall inputs take precedence?

REF: https://docs.splunk.com/Documentation/Splunk/9.1.3/Admin/Wheretofindtheconfigurationfiles


0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

Depends on whether within the TA the conf is in the local or default  directory. If it's in local, it depends on the alphabetical order of apps. Read the document once again. And do a btool --debug to verify.

Also you're not using deployer to distribute apps to HFs. You're using delpyment server for it. Deployer is for search head cluster.

View solution in original post

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Depends on whether within the TA the conf is in the local or default  directory. If it's in local, it depends on the alphabetical order of apps. Read the document once again. And do a btool --debug to verify.

Also you're not using deployer to distribute apps to HFs. You're using delpyment server for it. Deployer is for search head cluster.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...