Documentation: 3.4.1
Print Version Contents
This page last updated: 11/03/08 03:11pm

Configuration file list

Here is a list of all Splunk's configuration files with descriptions. Descriptions link to configuration instructions. Examples and specifications for each configuration file are contained in $SPLUNK_HOME/etc/system/README/.

File Purpose
alert_actions.conf Customize Splunk's global alerting actions.
app.conf Set up fields for your custom application.
audit.conf Configure auditing and event hashing.
authentication.conf Toggle between Splunk's built-in authentication or LDAP. Configure LDAP.
authorize.conf Configure roles, including granular access controls.
commands.conf Connect search commands to any custom search script.
deployment_server.conf Set up deployment servers and clients.
decorations.conf Customize dynamic event rendering.
eventdiscoverer.conf Set terms to ignore for typelearner (event discovery).
eventtypes.conf Create event type definitions.
field.conf Create multivalue fields and add search capability for indexed fields.
field_actions.conf Enable clickable actions on fields in SplunkWeb.
indexes.conf Manage and configure index settings.
inputs.conf Set up data inputs.
limits.conf Set various limits (such as maximum result size) for search commands.
literals.conf Customize the text displayed in Splunk Web.
multikv.conf Configure extraction rules for table-like events (eg ps, netstat, ls).
outputs.conf Set up forwarding, routing, cloning and data balancing.
prefs.conf Specify user preferences and dashboards for Splunk Web.
props.conf Set indexing property configurations, including timezone offset and custom sourcetype rules. Also map transforms to event properties.
restmap.conf Configure REST endpoints.
prefs.conf Specify user preferences and dashboards for Splunk Web.
regmonfilters.conf Create filters for Windows registry monitoring.
savedsearches.conf Define saved searches and their associated schedules and alerts.
segmenters.conf Customize segmentation rules for indexed events.
server.conf Enable SSL for Splunk's back-end and specify certification locations.
setup.conf Configure a Splunk application's interaction with other Splunk applications.
sourceclassifier.conf Terms to ignore (such as sensitive data) when creating a sourcetype.
sourcetypes.conf Machine-generated file that stores sourcetype learning rules created by sourcetype training.
streams.conf Configure additional streams for Live tail.
strings.conf Configure externalized product text strings.
sysmon.conf Set up Windows registry monitoring.
tags.conf Configure tags for extracted and indexed fields.
transactiontypes.conf Add additional transaction types for transaction search.
transforms.conf Configure regex transformations to perform on data inputs. Use in tandem with props.conf.
user_seed.conf Set a default user and password.
web.conf Configure Splunk Web, enable HTTPs.
wmi.conf Set up Windows management instrumentation (WMI) inputs.
Previous: Configure application directories    |    Next: About applications

Comments

No comments have been submitted.

Log in to comment.