When you are searching, configuration merging is slightly more complicated. When you are running a search, there is always an active user and app, and they come into play. The logical order looks like this:
- $SPLUNK_HOME/etc/system/default.
- $SPLUNK_HOME/etc/system/local.
- $SPLUNK_HOME/etc/apps/not app.
- Each app, other than the current app, is looped through in the ASCII order of the directory name (not the visible app name). Unlike merging outside of search, here z beats a.
- All configuration attributes that are shared globally are applied, first from default and then from local.
- $SPLUNK_HOME/etc/apps/app:
All configurations from default and then local are merged.
- $SPLUNK_HOME/etc/users/user/app/local