<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk ES pulling notables from other ES instance in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-ES-pulling-notables-from-other-ES-instance/m-p/676018#M18545</link>
    <description>&lt;P&gt;Hi Splunkers, today I have a "curiosity" about an architectural design I examinated last week.&lt;/P&gt;&lt;P&gt;The idea is the following: different regions (the 5 continents, in a nutshell), every one with its set of log sources and Splunk Components. All Splunk "items" are on prem: Forwarder, Indexers, SH and so on. More over, every region has 2 SH: one with Enterprise Security and another one without it. Untile now, "nothing new under the sun", like we say in Italy.&lt;BR /&gt;The new element, I men new for me and my experience, is the following one: there is a "centralized" cluster of SH, each one with Enterprise Security installed on it, that should collect the notables events from every regional ES. So, the flow about those component should be:&lt;/P&gt;&lt;P&gt;Europe ES Notables -&amp;gt; "Centralized" ES Cluster&lt;/P&gt;&lt;P&gt;America ES Notables -&amp;gt; "Centralized" ES Cluster&lt;/P&gt;&lt;P&gt;And so on. So, my wonder is: is there any doc about forward Notables events from a ES platform to another one? I searched but I didn't find anything about that (probabile I searched bad, I know).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 31 Jan 2024 08:54:28 GMT</pubDate>
    <dc:creator>SplunkExplorer</dc:creator>
    <dc:date>2024-01-31T08:54:28Z</dc:date>
    <item>
      <title>Splunk ES pulling notables from other ES instance</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-ES-pulling-notables-from-other-ES-instance/m-p/676018#M18545</link>
      <description>&lt;P&gt;Hi Splunkers, today I have a "curiosity" about an architectural design I examinated last week.&lt;/P&gt;&lt;P&gt;The idea is the following: different regions (the 5 continents, in a nutshell), every one with its set of log sources and Splunk Components. All Splunk "items" are on prem: Forwarder, Indexers, SH and so on. More over, every region has 2 SH: one with Enterprise Security and another one without it. Untile now, "nothing new under the sun", like we say in Italy.&lt;BR /&gt;The new element, I men new for me and my experience, is the following one: there is a "centralized" cluster of SH, each one with Enterprise Security installed on it, that should collect the notables events from every regional ES. So, the flow about those component should be:&lt;/P&gt;&lt;P&gt;Europe ES Notables -&amp;gt; "Centralized" ES Cluster&lt;/P&gt;&lt;P&gt;America ES Notables -&amp;gt; "Centralized" ES Cluster&lt;/P&gt;&lt;P&gt;And so on. So, my wonder is: is there any doc about forward Notables events from a ES platform to another one? I searched but I didn't find anything about that (probabile I searched bad, I know).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2024 08:54:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-ES-pulling-notables-from-other-ES-instance/m-p/676018#M18545</guid>
      <dc:creator>SplunkExplorer</dc:creator>
      <dc:date>2024-01-31T08:54:28Z</dc:date>
    </item>
  </channel>
</rss>

