Splunk Search

question on "local" folder

splunkatl
Path Finder

I am new to Splunk. I have two splunkforward servers, first server is already configured by someone else as splunk forwarder .I am trying to set up second server.
I untar the splunk forward software. I compared all folder and files in both server. I copied one folder "splunkuniversalforwader/etc/apps/Splunkforwader/local" from first to second one. boom everything is working fine.
My question is how is "local" folder get created in first server "splunkuniversalforwader/etc/apps/Splunkforwader?
Do I need run any CLI rather copying from other server?

0 Karma

Damien_Dallimor
Ultra Champion

Local folder is for any updates to configuration files that happen post installation ie: non-default settings.So the Local folder gets created when you make a configuration change ie: enabling an input, creating a field extraction via Splunk web etc...

0 Karma

Ayn
Legend

No, that is for regular app contents only.

0 Karma

Splunk_U
Path Finder

Can I create local folder @ /opt/splunk/share/splunk/search_mrsparkle/exposed/img/skins???

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...