Splunk Search

What is a good convention for config file organisation?

mikeydee
Explorer

Something to ponder while working from home...

I am planning on storing and managing my config files in Git. We recently ran into a few confusions managing our props files where our support teams got confused about the same props file (containing extracts and line breaking) getting deployed on search heads and on indexers.

So I thought I would come up with a convention that aligns to splunks phases. As per below...

<company>_search_<app>  search app for user dashboards and  reports (not to be held in git at present)
<company>_data_<app>     (field extractsion, calculated fields)
<company>_parse_<app>    (props and transforms for line breaking, timestamping etc)
<deployment>_<p|t>_<app>_<sub_component>  (inputs, outputs etc)  very much environment specific

Does anyone else worry about this stuff like I seem to and have a suggestion?

Mike

Tags (1)
0 Karma

mikeydee
Explorer
0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...