<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: App/Add-on in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/App-Add-on/m-p/681968#M113940</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233419"&gt;@PaulPanther&lt;/a&gt;&amp;nbsp;Thank you for your response, and does it not have any impact given that the indexers are not in a cluster?&lt;/P&gt;</description>
    <pubDate>Tue, 26 Mar 2024 09:00:43 GMT</pubDate>
    <dc:creator>BRFZ</dc:creator>
    <dc:date>2024-03-26T09:00:43Z</dc:date>
    <item>
      <title>App/Add-on</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/App-Add-on/m-p/681966#M113938</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have an architecture with a single SH and two indexers. I've installed the Splunk for Microsoft 365 add-on on the search head, so the collected logs are stored in the search head's index, but I want them to be stored on the indexers. Can you help me?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 26 Mar 2024 08:40:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/App-Add-on/m-p/681966#M113938</guid>
      <dc:creator>BRFZ</dc:creator>
      <dc:date>2024-03-26T08:40:56Z</dc:date>
    </item>
    <item>
      <title>Re: App/Add-on</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/App-Add-on/m-p/681967#M113939</link>
      <description>&lt;P&gt;1. Create the neccessary indexes on your indexer&lt;/P&gt;&lt;P&gt;2. Configure&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.0/DistSearch/Forwardsearchheaddata" target="_blank"&gt;Best practice: Forward search head data to the indexer layer - Splunk Documentation&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2024 08:57:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/App-Add-on/m-p/681967#M113939</guid>
      <dc:creator>PaulPanther</dc:creator>
      <dc:date>2024-03-26T08:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: App/Add-on</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/App-Add-on/m-p/681968#M113940</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233419"&gt;@PaulPanther&lt;/a&gt;&amp;nbsp;Thank you for your response, and does it not have any impact given that the indexers are not in a cluster?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2024 09:00:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/App-Add-on/m-p/681968#M113940</guid>
      <dc:creator>BRFZ</dc:creator>
      <dc:date>2024-03-26T09:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: App/Add-on</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/App-Add-on/m-p/681969#M113941</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/266281"&gt;@BRFZ&lt;/a&gt;&amp;nbsp; If you have no cluster the data are not replicated. So if one indexer goes down your search couldn't access all data.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2024 09:08:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/App-Add-on/m-p/681969#M113941</guid>
      <dc:creator>PaulPanther</dc:creator>
      <dc:date>2024-03-26T09:08:04Z</dc:date>
    </item>
  </channel>
</rss>

