Splunk Search

What is a good convention for config file organisation?

mikeydee
Explorer

Something to ponder while working from home...

I am planning on storing and managing my config files in Git. We recently ran into a few confusions managing our props files where our support teams got confused about the same props file (containing extracts and line breaking) getting deployed on search heads and on indexers.

So I thought I would come up with a convention that aligns to splunks phases. As per below...

<company>_search_<app>  search app for user dashboards and  reports (not to be held in git at present)
<company>_data_<app>     (field extractsion, calculated fields)
<company>_parse_<app>    (props and transforms for line breaking, timestamping etc)
<deployment>_<p|t>_<app>_<sub_component>  (inputs, outputs etc)  very much environment specific

Does anyone else worry about this stuff like I seem to and have a suggestion?

Mike

Tags (1)
0 Karma

mikeydee
Explorer
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...