<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic enterprise security notable are not same on all 3 SH enterprise security. in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/enterprise-security-notable-are-not-same-on-all-3-SH-enterprise/m-p/709701#M21416</link>
    <description>&lt;P&gt;We have SH cluster of 3 SH, where enterprise security notable are not same on all 3 SH enterprise security. And further when we check for last 15 min internal data that also &lt;SPAN&gt;vary&amp;nbsp;&lt;/SPAN&gt;with significant number (5 K to 10 k) than other 2 SH Member.&lt;/P&gt;</description>
    <pubDate>Fri, 24 Jan 2025 15:01:21 GMT</pubDate>
    <dc:creator>AShwin1119</dc:creator>
    <dc:date>2025-01-24T15:01:21Z</dc:date>
    <item>
      <title>enterprise security notable are not same on all 3 SH enterprise security.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/enterprise-security-notable-are-not-same-on-all-3-SH-enterprise/m-p/709701#M21416</link>
      <description>&lt;P&gt;We have SH cluster of 3 SH, where enterprise security notable are not same on all 3 SH enterprise security. And further when we check for last 15 min internal data that also &lt;SPAN&gt;vary&amp;nbsp;&lt;/SPAN&gt;with significant number (5 K to 10 k) than other 2 SH Member.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2025 15:01:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/enterprise-security-notable-are-not-same-on-all-3-SH-enterprise/m-p/709701#M21416</guid>
      <dc:creator>AShwin1119</dc:creator>
      <dc:date>2025-01-24T15:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: enterprise security notable are not same on all 3 SH enterprise security.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/enterprise-security-notable-are-not-same-on-all-3-SH-enterprise/m-p/709715#M21418</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249492"&gt;@AShwin1119&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;it's really strange, probably therewas some replication issue, did you checked the status of replication in the Cluster Manager Console?&lt;/P&gt;&lt;P&gt;Had you some stop of one or more of the indexers?&lt;/P&gt;&lt;P&gt;Have you a multisite or a single site Indexers Cluster?&lt;/P&gt;&lt;P&gt;If it's all OK, open a case to Splunk Support.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2025 15:45:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/enterprise-security-notable-are-not-same-on-all-3-SH-enterprise/m-p/709715#M21418</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-01-24T15:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: enterprise security notable are not same on all 3 SH enterprise security.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/enterprise-security-notable-are-not-same-on-all-3-SH-enterprise/m-p/709716#M21419</link>
      <description>&lt;P&gt;OK. Check shcluster-status. Check splunkd.log on those instances (and mongodb.log). If the state of the SHC is not in sync... that means something is off with replication or the overall cluster health.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2025 15:48:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/enterprise-security-notable-are-not-same-on-all-3-SH-enterprise/m-p/709716#M21419</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-01-24T15:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: enterprise security notable are not same on all 3 SH enterprise security.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/enterprise-security-notable-are-not-same-on-all-3-SH-enterprise/m-p/709750#M21425</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249492"&gt;@AShwin1119&lt;/a&gt;- I think its the same question here I have answered - &lt;A href="https://community.splunk.com/t5/Monitoring-Splunk/indexer-cluster-to-SH-cluster-replication-issue/m-p/709746/highlight/true#M10687" target="_blank"&gt;https://community.splunk.com/t5/Monitoring-Splunk/indexer-cluster-to-SH-cluster-replication-issue/m-p/709746/highlight/true#M10687&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think you are not forwarding the SH data to Indexers.&lt;/P&gt;&lt;P&gt;* Which is compulsory when you are using SHC.&lt;/P&gt;&lt;P&gt;* And best-practice in all SHs.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.4.0/DistSearch/Forwardsearchheaddata" target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs.splunk.com/Documentation/Splunk/9.4.0/DistSearch/Forwardsearchheaddata&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!!! Kindly upvote if it does!!!!&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jan 2025 08:28:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/enterprise-security-notable-are-not-same-on-all-3-SH-enterprise/m-p/709750#M21425</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2025-01-25T08:28:40Z</dc:date>
    </item>
  </channel>
</rss>

