How the Monitoring Console works
This topic lists the files that the Monitoring Console modifies in a Splunk Enterprise filesystem.
These files reside in $SPLUNK_HOME/etc/apps/splunk_monitoring_console/ unless indicated otherwise. This directory contains configuration files in both a default directory and, after Monitoring Console setup, a local directory. See About configuration file directories in the Admin Manual.
| File(s) | Information contained in file(s) | When populated | 
|---|---|---|
| app.conf | Basic information about the Monitoring Console: determines whether it is in distributed mode, and provides a short description for Splunk Web to use in Launcher. See app.conf.spec. | By default. Updated when you click Apply changes. | 
| distsearch.conf in etc/system/local | Contains stanzas that reference distributed search groups created by the Monitoring Console. The names of these groups are usually prefaced with dmc_group_*. For example: [distributedSearch:dmc_group_cluster_manager] | When you switch to distributed mode in Monitoring Console setup and click Apply changes | 
| dmc_alerts.conf | In some cases, you can edit thresholds in a platform alert without having to directly modify the search string for that alert. For such an alert, the Monitoring Console has a template of the search string, description string, and editable parameters. The template data, which is used in the Monitoring Console Alerts Setup page, is stored here, in stanzas named for the name of the saved search in default/savedsearches.conf. | By default | 
| lookups directory | Contains two important files: 
 | By default (on initial startup). Updated when you click Apply changes or Rebuild forwarder assets, respectively. | 
| macros.conf | Contains two types of macros: 
 See macros.conf.spec. | Search macros are stored here by default. Customizations are set when you edit one and click Save. | 
| props.conf | Search-time field extraction and lookup applications and evals. See props.conf.spec. | By default | 
| savedsearches.conf | Schedules and search strings for platform alerts. The saved search named DMC Forwarder - Build Asset Table runs when you enable forwarder monitoring. | By default | 
| splunk_monitoring_console_assets .conf | This file contains: 
 | When you click "Apply Changes" on Setup > General setup | 
| transforms.conf | Lookup definitions for assets.csv and forwarder csv file | By default | 
For more details about dmc_alerts.conf and splunk_monitoring_console_assets.conf, look in $SPLUNK_HOME/etc/apps/splunk_monitoring_console/README.