Admin Manual

 


How Splunk Works

Configuration file list

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

Configuration file list

Here is a list of all Splunk's configuration files with descriptions. Descriptions link to configuration instructions. Examples and specifications for each configuration file are contained in $SPLUNK_HOME/etc/bundles/README/.


FilePurpose
access_controls.confConfigure granular access control settings.
alert_actions.confCustomize Splunk's global alerting actions.
auth.confToggle between Splunk's built-in authentication or LDAP. Configure LDAP.
deployment_server.confSet up deployment servers and clients.
eventdiscoverer.confTune automatic event discovery.
eventtypes.confCreate event type definitions.
field_actions.confEnable clickable actions on fields in SplunkWeb.
indexes.confManage and configure index settings.
inputs.confSet up data inputs.
literals.confCustomize the text displayed in SplunkWeb.
metaevents.confOptionally add a preamble message for metaevents.
outputs.confSet up forwarding, routing, cloning and data balancing.
prefs.confSpecify user preferences and dashboards for SplunkWeb.
props.confSet indexing property configurations, including timezone offset and custom sourcetype rules. Also map transforms to event properties.
savedsearches.confDefine saved searches and their associated schedules and alerts.
segmenters.confCustomize segmentation rules for indexed events.
server.confEnable SSL and specify certification locations.
transforms.confConfigure regex transformations to perform on data inputs. Use in tandem with props.conf.
user_seed.confSet a default user and password.
web.confConfigure the SplunkWeb interface.

This documentation applies to the following versions of Splunk: 3.0 , 3.0.1 , 3.0.2 , 3.1 , 3.1.1 , 3.1.2 , 3.1.3 , 3.1.4 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.

Feedback submitted, thanks!