Hi,
We have Splunk cloud at an organization level. I had a requirement as such that I ended up installing Splunk Enterprise at a local machine and it worked for the solution. I had to copy props.conf, transform.conf file from "/etc/system/default" to "/etc/system/local" and made changes needed.
I am ready to ship the conf file to cloud server, however I just realized cloud server does not have "/etc/system/default/transform.conf" file. I am confused why it is not available. And, what would happen if I were ti add the new file "/etc/system/local/transform.conf". Will it work same as local(Splunk Enterprise) solution?
... View more