Getting Data In

Nullque setup help

Antioch
Path Finder

basically I am attempting to filter wmi eventlogs before they are indexed by the splunk server, I found a topic about this but I had a few more basic questions. I'm looking at the steps for setting up forwarding to the nullque here: http://docs.splunk.com/Documentation/Splunk/5.0.3/Deploy/Routeandfilterdatad but im not quite understanding the directions. First step is to edit props.conf, but when I look in my directory I have multiple props.conf files. Do I need to edit all of them? If not what is the path of the file I should be editing? I found the props.conf under splunkdir/etc/system/default, is this the right one? if so this file indicated it should be placed in the etc/system/local file, should I just be copying and pasting the whole file? or just the relevant sections? same goes for the transforms.conf, which one is the correct one? thanks for the help everyone

Tags (1)
0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

No you do not need to edit all of the files. Please look at this link below in the docs for file precedence. In most cases you'll create a new file under /system/local for props.conf and transforms.conf but it really depends. As long as you are not changing the default directory you are ok, since that is really for the base system or application. Changes within 'local' won't be overridden when you upgrade versions of Splunk.

http://docs.splunk.com/Documentation/Splunk/5.0.3/Admin/Wheretofindtheconfigurationfiles

View solution in original post

sdaniels
Splunk Employee
Splunk Employee

No you do not need to edit all of the files. Please look at this link below in the docs for file precedence. In most cases you'll create a new file under /system/local for props.conf and transforms.conf but it really depends. As long as you are not changing the default directory you are ok, since that is really for the base system or application. Changes within 'local' won't be overridden when you upgrade versions of Splunk.

http://docs.splunk.com/Documentation/Splunk/5.0.3/Admin/Wheretofindtheconfigurationfiles

softunlockiphon
New Member

good idea for all very nice hehehehe

0 Karma

Antioch
Path Finder

Thank you, the routing setup page should have a link back to this doc for reference.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...