Splunk Search

What is a good convention for config file organisation?

mikeydee
Explorer

Something to ponder while working from home...

I am planning on storing and managing my config files in Git. We recently ran into a few confusions managing our props files where our support teams got confused about the same props file (containing extracts and line breaking) getting deployed on search heads and on indexers.

So I thought I would come up with a convention that aligns to splunks phases. As per below...

<company>_search_<app>  search app for user dashboards and  reports (not to be held in git at present)
<company>_data_<app>     (field extractsion, calculated fields)
<company>_parse_<app>    (props and transforms for line breaking, timestamping etc)
<deployment>_<p|t>_<app>_<sub_component>  (inputs, outputs etc)  very much environment specific

Does anyone else worry about this stuff like I seem to and have a suggestion?

Mike

Tags (1)
0 Karma

mikeydee
Explorer
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...