Book Image

Implementing Splunk (Update)

Book Image

Implementing Splunk (Update)

Overview of this book

Table of Contents (20 chapters)
Implementing Splunk Second Edition
Credits
About the Authors
About the Reviewers
www.PacktPub.com
Preface
Index

The app directory structure


If you do much beyond building searches and dashboards, sooner or later you will need to edit files in the filesystem directly. All apps live in $SPLUNK_HOME/etc/apps/. On Unix systems, the default installation directory is /opt/splunk. On Windows, the default installation directory is C:\Program Files\Splunk.

This is the value that $SPLUNK_HOME will inherit on startup.

Stepping through the most common directories, we have:

  • appserver: This directory contains files that are served by the Splunk web app. The files that we uploaded in earlier sections of this chapter are stored in appserver/static.

  • bin: This is where command scripts belong. These scripts are then referenced in commands.conf. This is also a common location for scripted inputs to live, though they can live anywhere.

  • default and local: These two directories contain the vast majority of the configurations that make up an app.

    We will discuss these configurations and how they merge in Chapter 11, Configuring...