Separate configurations by purpose

Stepping through a typical installation, you would have configuration apps named like the following:

  • inputs-sometype: For some logical set of inputs, you would create an app. You could use machine purpose, source type, location, operating system, or whatever makes sense in your situation. Normally, I would expect machine purpose or source type.
  • props-sometype: This grouping should correspond to the grouping of the inputs, more or less. You may end up with props apps for more than one type, for instance machine type and location.
  • outputs-datacenter: When deploying across data centers, it is common to place Splunk indexers in each data center. In this case, you would need an app per data center.
  • indexerbase ...

Get Implementing Splunk 7 - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.