Wednesday, September 16, 2015

Splunk Configuration

Configuration for new instance of Splunk



1) Copy the apps file/folders


2) Modify following files to bind Application on fixed IP
  • \Splunk\etc\splunk-launch.conf (add SPLUNK_BINDIP=172.25.184.113 ) 
  • \Splunk\etc\system\default\web.conf ( modify the admin console)

3) Add fields extraction script end of the following file
  • \Splunk\etc\system\default\props.conf

4) Copy/past following local folder
  • \Splunk\etc\apps\search\local
  • \Splunk\etc\apps\learned\local
  • \Splunk\etc\apps\launcher\local

5) Modify GoogleMap file to view all points rather than 100 points
  • \Splunk\share\splunk\search_mrsparkle\exposed\js\build\splunkjs.min\mvc\googlemapview.js