Getting Data In

forwarder input and ouput conf priority

mpreddy
Communicator

i have an universal forwarder that has 2 apps . both the apps have their inputs and outputs. Both the apps are forwarding to 2 different indexers (like app1- idx1 app2-idx2). Suppose if i create an inputs.conf in an system level where it will forward?

what i understand is, File precedence in Splunk is:

System local directory: top priority
App local directories
App default directories
System default directory: lowest priority

So without outputs.conf define in system level which app will take an priority.

0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

You will need to understand full app context sorting priority also.. This is described in the document you copied from

To determine priority among the collection of apps directories, Splunk uses ASCII sort order. Files in an apps directory named "A" have a higher priority than files in an apps directory named "B", and so on. Also, all apps starting with an uppercase letter have precedence over any apps starting with a lowercase letter, due to ASCII sort order. ("A" has precedence over "Z", but "Z" has precedence over "a", for example.)

In addition, numbered directories have a higher priority than alphabetical directories and are evaluated in lexicographic, not numerical, order.

See doc file here : http://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Wheretofindtheconfigurationfiles#How_app_dir...

Additionally, you can have different outputs.conf, although this is against best practices. In these outputs you can specificy different output groups, and then in your inputs, direct these towards those specific output groups. This might be more along the lines of your question.

View solution in original post

pradeepkumarg
Influencer

Precedence order for inputs.conf and outputs.conf is independent of each other

Check below for detailed documentation

https://docs.splunk.com/Documentation/Splunk/6.5.1/Admin/Wheretofindtheconfigurationfiles

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

You will need to understand full app context sorting priority also.. This is described in the document you copied from

To determine priority among the collection of apps directories, Splunk uses ASCII sort order. Files in an apps directory named "A" have a higher priority than files in an apps directory named "B", and so on. Also, all apps starting with an uppercase letter have precedence over any apps starting with a lowercase letter, due to ASCII sort order. ("A" has precedence over "Z", but "Z" has precedence over "a", for example.)

In addition, numbered directories have a higher priority than alphabetical directories and are evaluated in lexicographic, not numerical, order.

See doc file here : http://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Wheretofindtheconfigurationfiles#How_app_dir...

Additionally, you can have different outputs.conf, although this is against best practices. In these outputs you can specificy different output groups, and then in your inputs, direct these towards those specific output groups. This might be more along the lines of your question.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...