<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Knowledge Bundle in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Knowledge-Bundle/m-p/583770#M11447</link>
    <description>&lt;P&gt;Hi. Have you looked at the distsearch settings wrt bundles?&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Limittheknowledgebundlesize" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Limittheknowledgebundlesize&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;So in the distsearch.conf there is both replicationWhitelist and replicationBlacklist.&lt;BR /&gt;&lt;BR /&gt;These are regex that specify what gets put into the knowledge bundles.&lt;/P&gt;&lt;P&gt;To find out exactly what is in place, use btool on your Splunk Search head and examine the setting. I like to add --debug in order that I can see exactly which app is contributing to the setting. By that I mean an app can have a distsearch.conf, you might have settings in etc/system/local/distsearch.conf etc&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/opt/splunk/bin/splunk btool distsearch list replicationWhitelist --debug

/opt/splunk/bin/splunk btool distsearch list replicationBlacklist --debug&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example for me&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/opt/splunk/bin/splunk btool distsearch list replicationWhitelist --debug
[replicationWhitelist]
/opt/splunk/etc/apps/splunk_archiver/default/distsearch.conf javabin = apps/splunk_archiver/java-bin/...
/opt/splunk/etc/system/default/distsearch.conf               kvstore = kvstore_*/...
/opt/splunk/etc/system/default/distsearch.conf               other = (system|(apps/(?!pdfserver)*)|users(/_reserved)?/*/*)/(bin|lookups)/...

(etc)&lt;/LI-CODE&gt;</description>
    <pubDate>Fri, 04 Feb 2022 20:00:27 GMT</pubDate>
    <dc:creator>burwell</dc:creator>
    <dc:date>2022-02-04T20:00:27Z</dc:date>
    <item>
      <title>Knowledge Bundle</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Knowledge-Bundle/m-p/583635#M11428</link>
      <description>&lt;P&gt;I was investigating bundle sizes coming from one of my SHC and came across several apps in the bundle that had the following in the lookup directory. Qualys is just one example there are several other apps where index.default and index.alive are present. Can someone tell me what these are and what they're doing in a knowledge bundle.&lt;/P&gt;&lt;P&gt;qualys_kb.csv_1534282613.index.default&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;qualys_kb.csv_1643803241.755269.cs.index.alive&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 20:07:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Knowledge-Bundle/m-p/583635#M11428</guid>
      <dc:creator>CarsonZa</dc:creator>
      <dc:date>2022-02-03T20:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: Knowledge Bundle</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Knowledge-Bundle/m-p/583770#M11447</link>
      <description>&lt;P&gt;Hi. Have you looked at the distsearch settings wrt bundles?&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Limittheknowledgebundlesize" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Limittheknowledgebundlesize&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;So in the distsearch.conf there is both replicationWhitelist and replicationBlacklist.&lt;BR /&gt;&lt;BR /&gt;These are regex that specify what gets put into the knowledge bundles.&lt;/P&gt;&lt;P&gt;To find out exactly what is in place, use btool on your Splunk Search head and examine the setting. I like to add --debug in order that I can see exactly which app is contributing to the setting. By that I mean an app can have a distsearch.conf, you might have settings in etc/system/local/distsearch.conf etc&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/opt/splunk/bin/splunk btool distsearch list replicationWhitelist --debug

/opt/splunk/bin/splunk btool distsearch list replicationBlacklist --debug&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example for me&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/opt/splunk/bin/splunk btool distsearch list replicationWhitelist --debug
[replicationWhitelist]
/opt/splunk/etc/apps/splunk_archiver/default/distsearch.conf javabin = apps/splunk_archiver/java-bin/...
/opt/splunk/etc/system/default/distsearch.conf               kvstore = kvstore_*/...
/opt/splunk/etc/system/default/distsearch.conf               other = (system|(apps/(?!pdfserver)*)|users(/_reserved)?/*/*)/(bin|lookups)/...

(etc)&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 04 Feb 2022 20:00:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Knowledge-Bundle/m-p/583770#M11447</guid>
      <dc:creator>burwell</dc:creator>
      <dc:date>2022-02-04T20:00:27Z</dc:date>
    </item>
    <item>
      <title>Re: Knowledge Bundle</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Knowledge-Bundle/m-p/583773#M11449</link>
      <description>&lt;P&gt;Thank you for the response. I am familiar with replicationblacklist, however my questions is what are index.default and index.alive doing in a lookup directory in a knowledge bundle.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 21:29:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Knowledge-Bundle/m-p/583773#M11449</guid>
      <dc:creator>CarsonZa</dc:creator>
      <dc:date>2022-02-04T21:29:13Z</dc:date>
    </item>
    <item>
      <title>Re: Knowledge Bundle</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Knowledge-Bundle/m-p/583782#M11450</link>
      <description>&lt;P&gt;I have seen even some tsidx files there… I just found those, so I haven’t have time to figure out wha5 and why those are there. I hope that someone knows that already.&lt;/P&gt;&lt;P&gt;Splunk 7.3.3 SHC with multisite IDX cluster.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 21:58:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Knowledge-Bundle/m-p/583782#M11450</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-02-04T21:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: Knowledge Bundle</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Knowledge-Bundle/m-p/583798#M11452</link>
      <description>&lt;P&gt;Hi. I see people talking about the issue on Splunk's slack usersgroups instance in the admin channel.&lt;/P&gt;&lt;P&gt;I pinged you there.&lt;/P&gt;&lt;P&gt;There is mention that the .alive indicates that activity is happening.&lt;/P&gt;&lt;P&gt;If you don't want that in your knowledge bundle I would blacklist it, but it is a good question.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Feb 2022 00:44:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Knowledge-Bundle/m-p/583798#M11452</guid>
      <dc:creator>burwell</dc:creator>
      <dc:date>2022-02-05T00:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: Knowledge Bundle</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Knowledge-Bundle/m-p/583802#M11454</link>
      <description>&lt;P&gt;Thank you,&amp;nbsp; im gonna add the details from Slack for anyone else who might come across this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"...Once a lookup exceeds the max memtable limit, Splunk will bucketify it, creating a kind of mini index."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So if you're&amp;nbsp;seeing index.alive or index.default just backlist the respective lookup in &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.4/Admin/Distsearchconf#REPLICATION_DENY_LIST_OPTIONS" target="_self"&gt;distsearch.conf&lt;/A&gt; and in rare circumstance you could increase max_mem_usage_mb in &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.4/Admin/Limitsconf#.5Bdefault.5D" target="_self"&gt;limits.conf&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Feb 2022 03:40:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Knowledge-Bundle/m-p/583802#M11454</guid>
      <dc:creator>CarsonZa</dc:creator>
      <dc:date>2022-02-05T03:40:25Z</dc:date>
    </item>
  </channel>
</rss>

