The merging order when searching

When you are searching, configuration merging is slightly more complicated. When you are running a search, there is always an active user and app, and they come into play. The logical order looks like this:

  1. $SPLUNK_HOME/etc/system/default.
  2. $SPLUNK_HOME/etc/system/local.
  3. $SPLUNK_HOME/etc/apps/not app.
    • Each app, other than the current app, is looped through in the ASCII order of the directory name (not the visible app name). Unlike merging outside of search, here z beats a.
    • All configuration attributes that are shared globally are applied, first from default and then from local.
  4. $SPLUNK_HOME/etc/apps/app:

All configurations from default and then local are merged.

  1. $SPLUNK_HOME/etc/users/user/app/local

Get Implementing Splunk 7 - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.