Admin Manual

 


Splunk configuration methods

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

Splunk configuration methods

Splunk maintains its configuration information in a set of configuration files. You can configure Splunk by using any of these methods:

All of these methods change the contents of the underlying configuration files.

To configure and manage distributed environments, you can use Splunk's deployment server.

Configuration files

Most of Splunk's configuration information is stored in .conf files. These files are located under your Splunk installation directory (usually referred to in the documentation as $SPLUNK_HOME) under /etc/system. You can make changes to these files using a standard text editor. Before you begin editing configuration files, read the material in the topic called About configuration files.

Splunk Manager

You can perform most common configuration tasks with Splunk Manager in Splunk Web. Splunk Web runs by default on port 8000 of the host on which it is installed:

where <hostname> is the name of the machine Splunk is running on.

To access Splunk Manager, log into Splunk Web and click Manager in the upper right hand corner.

Splunk CLI

Many configuration options are available via the CLI. These options are documented in their respective topics, or you can get a complete CLI help reference with the command help while Splunk is running:

./splunk help

For more information about the CLI, refer to "About the CLI" in this manual.

Managing a distributed environment

The Splunk deployment server provides centralized management and configuration for distributed environments. You can use it to deploy sets of configuration files or other content to groups of Splunk instances across the enterprise.

For information about managing deployments, refer to "Deploy to other Splunk instances" in this manual.

Restarting after configuration changes

Many changes to configuration files require you to restart Splunk. Check the configuration file or its reference topic to see whether a particular change requires a restart.

When you make changes in the Manager, the Manager will let you know if you have to restart.

These changes require additional or different actions before they will take effect:

| extract reload=T

This documentation applies to the following versions of Splunk: 4.1 , 4.1.1 , 4.1.2 , 4.1.3 , 4.1.4 , 4.1.5 , 4.1.6 , 4.1.7 , 4.1.8 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.

Feedback submitted, thanks!