Very tricky!!! Answer is NOT D as etc/users/admin/local is not a valid directory . it is missing the <user app>.... to be correct it would look like this... etc/users/admin/<app name>/local .. so answer is C. Also reference Data Admin class PDF page 20 search time precedence diagram..
The question is about "search time" no "index time" (Global context) so the App/User context has the highest precedence, the answer is D
https://docs.splunk.com/Documentation/Splunk/7.3.0/Admin/Wheretofindtheconfigurationfiles
Agreed D. Adding further clarity and quoting same Splunk reference URL from @giubal"
"To keep configuration settings consistent across peer nodes, configuration files are managed from the cluster master, which pushes the files to the slave-app directories on the peer nodes. Files in the slave-app directories have the highest precedence in a cluster peer's configuration. Here is the expanded precedence order for cluster peers:
1.Slave-app local directories -- highest priority
2. System local directory
3. App local directories
4. Slave-app default directories
5. App default directories
6. System default directory --lowest priority
D, check page 121 os the System Admin official Splunk course.
Search-Time Precedence (App/User Context)
Precedence order where 1 is highest priority:
1. Current user directory for app
etc/users/user/appname/local
2. App directory - running app
etc/apps/appname/local
etc/apps/appname/default
3. App directories - all other apps*
etc/apps/appname/local
etc/apps/appname/default
4. System directories
etc/system/local
etc/system/defaultPrecedence order
tricky question, however, if you follow the documentation this is the precedence for search time: Precedence order
1. Current user directory for app
etc/users/user/appname/local
2. App directory - running app
etc/apps/appname/local
etc/apps/appname/default
3. App directories - all other apps*
etc/apps/appname/local
etc/apps/appname/default
4. System directories
etc/system/local
etc/system/default
It’s ‘D’.
During search time, the directory of configuration files with the highest precedence is:
**D. $SPLUNK_HOME/etc/users/admin/local**
The order of precedence for configuration files in Splunk, from highest to lowest, is as follows:
1. **$SPLUNK_HOME/etc/users/<username>/<appname>/local**
2. **$SPLUNK_HOME/etc/users/<username>/<appname>/default**
3. **$SPLUNK_HOME/etc/apps/<appname>/local**
4. **$SPLUNK_HOME/etc/apps/<appname>/default**
5. **$SPLUNK_HOME/etc/system/local**
6. **$SPLUNK_HOME/etc/system/default**
This hierarchy ensures that user-specific settings (which are stored in the `$SPLUNK_HOME/etc/users` directory) take precedence over app-specific settings and system-wide settings.
1. Current user directory for app etc/users/user/appname/local
2. App directory -running app etc/apps/appname/local etc/apps/appname/default
3. App directories -all other apps* etc/apps/appname/local etc/apps/appname/default
4. System directories etc/system/localetc/system/default
PDF Page 341
Since the path of D is wrong, I would go with C as the next in line to take precedence and its the highest for this question
D is very tricky!
It would have been the correct answer if it was D. $SPLUNK_HOME/etc/users/admin/app_name/local
Since there is no app in the path it doesn't exist.
INDEX time: sys local, app local, app default, sys default
SEARCH time: user app (user directory), running app (local and defautl), other apps (local and default), sys directories (local and default).
so D!
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
dwallen41
Highly Voted 4 years, 2 months agoSPLTony
1 year, 5 months agoSCARODJ
9 months, 2 weeks agogiubal
Highly Voted 4 years, 10 months agoucsdmiami2020
3 years, 4 months agoAngusBlack
3 years, 7 months agohesbee
3 years, 6 months agoMarco63
2 years, 10 months ago3bd8ac0
Most Recent 1 week, 6 days ago3bd8ac0
2 weeks, 4 days ago65aab2c
4 months, 1 week agoFrank_Rai
10 months, 2 weeks agolance_grown
1 year, 3 months agobobixaka
1 year, 3 months agoSplunkor
1 year, 4 months agoSplunkor
1 year, 4 months agotmmt
2 years agopro12345
2 years, 5 months agoemlch
2 years, 5 months agotmmt
2 years agoking1993
2 years, 10 months agoBlueRoselia
2 years, 12 months ago[Removed]
3 years, 1 month ago[Removed]
3 years, 1 month ago[Removed]
3 years agoApis
3 years, 1 month ago