Back to Floor
The Config Labyrinth • Room 3

Key Configuration Files

inputs.conf defines what data Splunk collects — file monitors, network listeners, scripted inputs, and more.

outputs.conf controls where data is forwarded to — which indexers or indexer clusters receive the data.

props.conf and transforms.conf work together for data parsing — source type recognition, timestamp extraction, field extraction, and event breaking.

server.conf contains general server settings like the server name, SSL configuration, and replication settings.

Knowledge Check

Prove your understanding to clear the room (Rewards XP)
Drag items to their correct zone (or tap item then tap zone on mobile)
Defines file monitors and network ports
Specifies target indexers for forwarding
Controls timestamp extraction rules
Sets the Splunk server name and SSL
inputs.conf
outputs.conf
props.conf
server.conf