How the DMC works
This topic lists the files that the Distributed Management Console modifies in a Splunk Enterprise filesystem.
These files reside in
$SPLUNK_HOME/etc/apps/splunk_management_console/ unless indicated otherwise.
|File(s)||What DMC information is in there||When populated|
|app.conf||Basic information about the DMC: determines whether it is in distributed mode, and provides a short description for Splunk Web to use in Launcher. See app.conf.spec.||By default. Updated when you click Apply changes.|
|distsearch.conf in etc/system/local||Contains stanzas that reference distributed search groups created by the DMC. The names of these groups are usually prefaced with dmc_group_*. For example:
||When you switch to distributed mode in DMC setup and click Apply changes|
|dmc_alerts.conf||In some cases, you can edit thresholds in a platform alert without having to directly modify the search string for that alert. For such an alert, the DMC has a template of the search string, description string, and editable parameters. The template data, which is used in the DMC Alerts Setup page, is stored here, in stanzas named for the name of the saved search in default/savedsearches.conf.||By default|
|lookups directory||Contains two important files:
||By default (on initial startup). Updated when you click Apply changes or Rebuild forwarder assets, respectively.|
|macros.conf||Contains two types of macros:
| Search macros are stored here by default.
Customizations are set when you edit one and click Save.
|props.conf||Search-time field extraction and lookup applications and evals. See props.conf.spec.||By default|
|savedsearches.conf||Schedules and search strings for platform alerts. The saved search named DMC Forwarder - Build Asset Table runs when you enable forwarder monitoring.||By default|
|This file contains:
||When you click "Apply Changes" on Setup > General setup|
|transforms.conf||Lookup definitions for assets.csv and forwarder csv file||By default|
For more details about dmc_alerts.conf and splunk_management_console_assets.conf, look in
What can the DMC do?
Multi-instance deployment DMC setup steps
This documentation applies to the following versions of Splunk® Enterprise: 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11