November 2018
Beginner
298 pages
7h 51m
English
Splunk uses configuration (.conf) files to control nearly every aspect of its operation. There are numerous configuration files with the same name layered inside of different directories that affect users, an app, or the system as a whole, so upon startup, Splunk merges the contents of these files based upon a directory location-based prioritization scheme to achieve an overall working configuration in memory. The rules Splunk follows when merging these files are as follows:
Read now
Unlock full access