Deployment Architecture

what do you put in your .gitignore file for a system backup?

awurster
Contributor

Splunkers - what do you all put in your gitignore files when doing a backup? primarily concerned with a Search Head in a distributed deployment, and backing up configs, apps, etc

Tags (3)
0 Karma
1 Solution

awurster
Contributor

well this is what i use anyhow.
https://bitbucket.org/snippets/atlassian/TBXp

### exclude ###
#############

# default binaries
bin/*

# default configs #
etc/system/*
etc/apps/search/*

# key files and hashes #
etc/auth/
etc/passwd

# default apps #
etc/apps/search/*
etc/apps/sample_app/
etc/apps/launcher/
etc/apps/gettingstarted/
etc/apps/introspection_generator_addon/
etc/apps/framework
etc/apps/SplunkLightForwarder/
etc/apps/splunk-sdk-python-master/

# large lookup files #
etc/apps/sos/lookups/
etc/apps/secint/lookups/

# internals
etc/modules/
etc/anonymizer/
etc/myinstall/
etc/init.d/
etc/openldap/
etc/.?*

include/
lib/
openssl/
share/
var/
master.zip
/.?*
/*.txt


### include ###
#############

# custom scripts #
!bin/scripts/

# global configs #
!etc/system/local/
!etc/apps/search/local/
!etc/splunk-launch.conf

View solution in original post

awurster
Contributor

well this is what i use anyhow.
https://bitbucket.org/snippets/atlassian/TBXp

### exclude ###
#############

# default binaries
bin/*

# default configs #
etc/system/*
etc/apps/search/*

# key files and hashes #
etc/auth/
etc/passwd

# default apps #
etc/apps/search/*
etc/apps/sample_app/
etc/apps/launcher/
etc/apps/gettingstarted/
etc/apps/introspection_generator_addon/
etc/apps/framework
etc/apps/SplunkLightForwarder/
etc/apps/splunk-sdk-python-master/

# large lookup files #
etc/apps/sos/lookups/
etc/apps/secint/lookups/

# internals
etc/modules/
etc/anonymizer/
etc/myinstall/
etc/init.d/
etc/openldap/
etc/.?*

include/
lib/
openssl/
share/
var/
master.zip
/.?*
/*.txt


### include ###
#############

# custom scripts #
!bin/scripts/

# global configs #
!etc/system/local/
!etc/apps/search/local/
!etc/splunk-launch.conf
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...