All Apps and Add-ons

File/Directory Information Input: Is there a way to point this add-on at a Clustered Index?

FrankBurns
New Member

Simple question. I want to point this add-on at a search head that can see an indexing cluster and have it store its output on an index in the cluster (not a local one). You can't do this via the UI as it only shows local indexes. I assume I can just edit the relevant config file but I can't find the config file.

0 Karma

msivill_splunk
Splunk Employee
Splunk Employee

So if the file/directory to poll is on a different machine from indexing cluster you might want to consider using the universal forwarder to send data to the indexing cluster.

Universal forwarder docs - http://docs.splunk.com/Documentation/Splunk/6.4.3/Data/Usingforwardingagents

0 Karma

FrankBurns
New Member

Why would I add a Universal Forwarder to a search head?

The search head already has an outputs.conf that allows forwarding to the index cluster. I just need to point this app at the right index name.

0 Karma

msivill_splunk
Splunk Employee
Splunk Employee

So generally if you are scaling out Splunk people tend to split it across 3 tiers, the search head layer, the indexing layer, and the data forwarder layer. These layers generally tend to be on different machines.

So the suggestion of universal forwarder was more based on long term scaling for your Splunk instance.

0 Karma

FrankBurns
New Member

Thanks for your input but it isn't really addressing the original question, I am afraid. Whether a UF is there or not won't help with the fact that I currently don't have a way to tell the app to point to a clustered index.

0 Karma

msivill_splunk
Splunk Employee
Splunk Employee
0 Karma

msivill_splunk
Splunk Employee
Splunk Employee

Are you trying to get File/Directory Input data onto an indexing cluster? Is the search head able to query data from the indexing cluster at the moment?

0 Karma

FrankBurns
New Member

Yes to both questions.

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...