Splunk Search

Config consolidation

rhysjones
Path Finder

Hi Everyone,

Just throwing this one out there. Our install is a couple of years old and has gone through several upgrades and a server move. Over that time we have slowly learned more and more about how it all hangs together, mended our ways, and gradually improved things. We were struck with the 5.0 bug where we can;t use the GUI so I have been elbows deep in the config files doing it the real way. In doing so I was having a look at the various field extractions, saved searches, indexs, inputs, and so forth. Due to the way the WEB interface cleverly places settings in the config files of the app you were in at the time, the various configs are all over the place. Spread out over system local, apps, and users.

So the question, would it be sensible to go through and relocate all the config back into more appropriate config files (ie indexes and inputs in the system local, extractions in the app, and so forth) ? Or should I just leave well enough alone ?

Thanks in advance for any wise comments and advice.

Rhys

0 Karma

jmheaton
Path Finder

I'm actually sitting in the same boat here.
Been searching for a way to do this for a couple weeks.

I'm about to test merging configs onto a dev environment. I'll post back when i find something interesting.

0 Karma

rhysjones
Path Finder

Thanks and good luck. We did a bit of a cleanup in the end ourselves and it worked ok.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...