The app directory structure

If you do much beyond building searches and dashboards, sooner or later you will need to edit files in the filesystem directly. All apps live in $SPLUNK_HOME/etc/apps/. On Unix systems, the default installation directory is /opt/splunk. On Windows, the default installation directory is C:\Program Files\Splunk.

This is the value that $SPLUNK_HOME will inherit on startup.

Stepping through the most common directories, we have:

  • appserver: This directory contains files that are served by the Splunk web app. The files that we uploaded in earlier sections of this chapter are stored in appserver/static.
  • bin: This is where command scripts belong. These scripts are then referenced in commands.conf. This is also a common location ...

Get Implementing Splunk - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.