icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Conf Editor for Splunk
SHA256 checksum (conf-editor-for-splunk_030.tgz) 152aa00f1d9076746f8a40e4945f4221c4898cd798a9613225bb69d1b4bf33c0 SHA256 checksum (conf-editor-for-splunk_020.tgz) 66f3325164301c53e617525ca112ae6efbfe15469ca6acc6b2aa01bbc4268205 SHA256 checksum (conf-editor-for-splunk_011.tgz) 231198d0dd0714f6e1137e91e8ec9a82cac1e0a17867aaacc7289694716da765 SHA256 checksum (conf-editor-for-splunk_010.tgz) 565273e93dccc01baea4ad2a07afa49163afd832c3a8f5d731726933db053ba5
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate


Conf Editor for Splunk

Splunk Cloud
Splunk Labs
This app provides a view for editing *.conf files in user-specified ...app/local directory as well as conf files in the system/local directory.
The app also includes a view for normalizing search fields (by default, this is tailored towards ITSI fields).
All operations are performed using Splunk REST api and no direct changes are made to the files system.

Conf Editor Documentation


The app includes three views:

Edit Conf File

This view for editting/adding conf files at the app level.

Edit System Conf

Edit system-level configuration files.

Normalize Fields

This view is for EVAL and EXTRACT fields in props.conf.

Edit Conf File

This is the general purpose for arbitrary conf files that can be saved either at the user namespace etc/users/{user}/{app}/local/... or at the app namespace etc/apps/{app}/local/...

Some configuration files have been excluded from the dropdown as they are only valid to be saved under the system namespace. These can be edited using the System Conf File page. However, the list used is not guaranteed to be exhaustive, so some conf files might fail to save (or not show up at all) using both this app conf editor and the system conf editor. In this case, and any other case of repeated failure to save, assume this app will be unable to edit such files.

The Conf Details page allows for selecting from a list of configuration files available in the Splunk instance (a new file can also be added). All changes are made to the whole stanza at a time. The app context and sharing settings determine the directory and visibility, respectively, of the properties that are modified in the file.

For example, after selecting the following:
- "tags" file (tags.conf)
- stanza: "test"
- app context of "Conf Editor"
- sharing of "app"

Changes will be written to the path:


And the file will look like so:




  • It is important to be familiar with the required format for each conf file. The UI does not run any validation on the values. Read the Splunk manual

  • The editor will allow creating new stanzas that might not be valid (but nevertheless allowed through the Splunk REST api).

  • For example, the stanza [source*] is not valid, (wild card). No fields will be matched in searches (this is a search-time error) but the editor UI will not report any error during creation.

Normalize Fields

This page allows adding, update and deleting fields (EVAL and EXTRACT only) in props.conf for a specific app or sharing context.
This app does not support (nor does it make changes to) fields defined using the TRANSFORM directive.

Changes to the props.conf file are made only by calling the respective REST api endpoints (for editing and setting acl) on knowledge objects.


The app includes a custom configuration (conf-editor-settings.conf).
There's currently only one relevant stanza in the configuration file.

[field-list] defines the optional and mandatory fields, it has keys:
- optional - fields to be listed as optional category in the UI.
- mandatory - fields to be listed as mandatory in the UI.
Both keys expect a comma separated list of values. There's a default list that matches the ITSI fields. Read more here.
This list determines the suggested field in the Normalize Fields page.


  • The app includes a default web.conf with two expose directives, this is required in order to be able to access the REST endpoints that allow making changes to props.conf. This means a Splunk restart is required (after app installation) before using the Normalize Fields

  • When a new stanza is created in props.conf under Normalize Fields. Deleting all the keys for the stanza may not automatically delete that stanza.

For example, if the following were created.


And the key=value property was deleted.
The prop.conf file will look like so:


This is intentional for now, as there might be other properties created under the stanza that the app does not make changes to (i.e a TRANSFORM-{} property)

Edit System Conf:

This page is specifically for configurations files withing that can only be saved at the system level (instead of app/user namespace).

The configuration selection dropdown is mutually exclusive with that show in the regular conf editor page. The web.conf file is the only configuration file that appears on both.

Using the system conf editor requires a lot more comfort and knowledge with configuration files.

Because they are at the system level some of the conf files control instance-level settings like maximum memory usage.

Be sure to familiarize yourself with the configuration file you wish to change before using the page.
Use the Splunk Admin manual when in doubt.

No guidance or guarantee is provided in the UI for valid or recommended values.


  • Because of how Splunk loads changes to configuration files, most of the files available to edit here require a restart before the changes will actually be applied within Splunk.
  • Because of how the api the UI uses for managing conf files. The page might show old/default values for a certain key after it has been updated/saved. This doesn't mean the respective changes in system/local have not been made - it just means Splunk hasn't loaded it yet. Read the documentation for each configuration to determine if a restart is required for Splunk to pick up changes.

  • To minimize invalid stanzas and key/value pairs. Only pre-existing stanzas and keys will be shown.

  • New stanzas cannot be created.
  • New keys cannot be added and existing key names cannot be changed.

General Notes And Troubleshooting

  • Changes are never made to default configuration files (in the default directory), edits are only applied to local conf files, the file(s) will be created if it doesn't already exist. Read more about Splunk configuration files

  • The editor makes use of the current user's authenticated session to make REST api calls. If the current user does not have the proper permissions to view or edit to files, then the file might not appear, be disabled or fail to save, depending on the acl rules.

Any errors relating authentication requests are also linked to the current browser session. Authenticated sessions might be invalidated when using an "Incognito/Private" window. Refreshing the tab should fix the issue, otherwise use a regular browser window when possible to avoid errors with sessions and cookies.

Release Notes

Version 0.3.0
March 24, 2021

New Features:

  • Adds new view/page for editing system-specific conf files.


  • Adds prefetching to the stanza selector. In the conf editor view, user can select or add new stanza. In system conf, adding new stanzas is not allowed.
  • Fix logic for overriding values in default with new local key/value(s).
  • Misc. bug fixes and clean up.
Version 0.2.0
March 2, 2021

Add new view for editing other configuration files besides props.conf. Only works with files that can be saved into the app/local directory.
More details in details/docs.

Version 0.1.1
Feb. 10, 2021
  • minor fixes and changes to editor form.
Version 0.1.0
Feb. 10, 2021

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.