Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How do I figure out why custom conf files are not being imported?

$
0
0
I am in the process of moving my indexer to a new server, and in the process, I thought it would be a good idea to combine the multiple configuration files that were scattered through $SPLUNK_HOME. The files I condensed are indexes.conf, transforms.conf, props.conf, serverclasses.conf (did not stick all of it in 1 file, the serverclasses.conf files went to a serverclasses.conf file). I put the new configuration files in `$SPLUNK_HOME/etc/system/custom_configs` (so they were not higher than etc/local files). However when I rebooted and ran btool none of my configurations were imported. Thinking I had read the guide on the configurations incorrectly, also tried `$SPLUNK_HOME/etc/system/local/custom_configs` and `$SPLUNK_HOME/etc/apps/custom_configs`, but neither local corrected the issue. I checked the permissions and even set the owner as splunk. I am at a loss as to what I am doing wrong. My environment is pretty simple: Version: 6.3.3 No. Indexers: 1 Roles for indexer: all Thanks, Sean

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>