Getting Data In

sequence/order of conf files splunk process?

bheemireddi
Communicator

Hi,
Would like to know what sequence/order Splunk processes the *.conf files, suppose if I have inputs.conf configured in different locations $SPLUNKHOME/etc/apps/search, $SPLUNKHOME/etc/system/local etc. Does one gets precedence over the other?

Also I would like to monitor only WARN and ERROR messages in Splunk log files ($SPLUNKHOME/var/log/splunk)
Does the white list work for this purpose? Not sure if it looks only the file names? I used as below, but doesn't seem to work
whiltelist = (WARN|ERROR)

Thanks for your help!

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...