Getting Data In

splunk config such as props.conf index.conf limits.conf in distributed environment

perlish
Communicator

Hi,everyone
I have an distributed environment.
one search header one forwarder and six indexer.
After i config props.conf in search header, wheather i need to copy props.conf to the six indexer?
Same question as limits.conf and index.conf.

I fount even if i didn`t copy props.conf to indexer, i still can use the difined field to search.
But if this,will the performance worse than copy props.conf to indexer?

Thanks.

0 Karma

gfuente
Motivator

Some props configurations had to be in the SH and other had to be in the IDX, so you just need to configure the settings in the right place.

Check this:

http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F

Regards

0 Karma

kml_uvce
Builder

search head distribute knowledge bundles(system, apps, users directory) to indexers when connection is established.
Indexed related things you can configure in indexers like set the size of an index etc...
search time field extration distribute to indexer by search head when connection is established with indexer

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...