Deployment Architecture

how to assign data to an index?

vnguyen46
Contributor

I have data from different sources already forwarded to a forwarders. Indexes already created on a deployment-master combined server, next how can I assign the data per source to a desired index?

Thanks,

0 Karma
1 Solution

woodcock
Esteemed Legend

If you created an app in the deployment-apps directory on your Deployment Server and it has an inputs.conf that defines index values, you still have to deploy this app to your indexers by creating a serverclass inside of $SPLUNK_HOME/etc/system/local/serverclass.conf and add a whitelist setting to this serverclass that contains the identities of your indexers. Then add the app that you created to the serverclass. Then restart the Deployment Server and let the magic happen.

View solution in original post

0 Karma

vnguyen46
Contributor

Excellent information - thank you everyone.

0 Karma

woodcock
Esteemed Legend

If you created an app in the deployment-apps directory on your Deployment Server and it has an inputs.conf that defines index values, you still have to deploy this app to your indexers by creating a serverclass inside of $SPLUNK_HOME/etc/system/local/serverclass.conf and add a whitelist setting to this serverclass that contains the identities of your indexers. Then add the app that you created to the serverclass. Then restart the Deployment Server and let the magic happen.

0 Karma

Anantha123
Communicator
0 Karma

vnguyen46
Contributor

Do I need to update these .conf files on the deployment server or other instances?

Thanks,

0 Karma

iamsplunker31
Path Finder

Hi @vnguyen46 , You need to update the indexes.conf in ClusterMaster and push it to indexers and inputs.conf on Deployment server push it to forwarders
Update serverclass.conf in DS(Deployment Server)
props.conf is not mandatory

0 Karma

Anantha123
Communicator

You have to update in index.conf ,input.conf ,props.conf, serverclass.conf files to assign data to desired index.

Thanks
Anantha.

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...