<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to store or index data from multiple clients that have multiple servers? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-store-or-index-data-from-multiple-clients-that-have/m-p/224162#M43882</link>
    <description>&lt;P&gt;Hello. &lt;/P&gt;

&lt;P&gt;First time I'm posting a question, and a relative new to Splunk so I apologize up front if this has already been asked and answered, or if this is a silly question. We are planning to use Splunk for log monitoring.&lt;/P&gt;

&lt;P&gt;Scenario:&lt;BR /&gt;
Let's say we have 3 clients (A,B,C) to simplify the situation (in real situation we have more than 3 clients).&lt;BR /&gt;
Each client has 20 servers to monitor.&lt;BR /&gt;
Currently, when problem happens on Client A, we manually login to every server that belong to Client A and start checking logs.&lt;BR /&gt;
We want to use Splunk to help us to speed up investigation in finding issue.&lt;/P&gt;

&lt;P&gt;Question:&lt;BR /&gt;
How should I setup Splunk to segment or partition logs? &lt;BR /&gt;
logs from Client A are stored and indexed as Client-A logs&lt;BR /&gt;
logs from Client B are stored and indexed as Client-B logs.&lt;BR /&gt;
logs from Client C are stored and indexed as Client-C logs.&lt;/P&gt;

&lt;P&gt;Reason: When issue happens on Client-A, I want to view and analyze logs from Client-A only.&lt;BR /&gt;
I don't want to see logs from Client-B and Client-C.&lt;/P&gt;

&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
    <pubDate>Wed, 28 Sep 2016 15:27:38 GMT</pubDate>
    <dc:creator>makincerdas</dc:creator>
    <dc:date>2016-09-28T15:27:38Z</dc:date>
    <item>
      <title>How to store or index data from multiple clients that have multiple servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-store-or-index-data-from-multiple-clients-that-have/m-p/224162#M43882</link>
      <description>&lt;P&gt;Hello. &lt;/P&gt;

&lt;P&gt;First time I'm posting a question, and a relative new to Splunk so I apologize up front if this has already been asked and answered, or if this is a silly question. We are planning to use Splunk for log monitoring.&lt;/P&gt;

&lt;P&gt;Scenario:&lt;BR /&gt;
Let's say we have 3 clients (A,B,C) to simplify the situation (in real situation we have more than 3 clients).&lt;BR /&gt;
Each client has 20 servers to monitor.&lt;BR /&gt;
Currently, when problem happens on Client A, we manually login to every server that belong to Client A and start checking logs.&lt;BR /&gt;
We want to use Splunk to help us to speed up investigation in finding issue.&lt;/P&gt;

&lt;P&gt;Question:&lt;BR /&gt;
How should I setup Splunk to segment or partition logs? &lt;BR /&gt;
logs from Client A are stored and indexed as Client-A logs&lt;BR /&gt;
logs from Client B are stored and indexed as Client-B logs.&lt;BR /&gt;
logs from Client C are stored and indexed as Client-C logs.&lt;/P&gt;

&lt;P&gt;Reason: When issue happens on Client-A, I want to view and analyze logs from Client-A only.&lt;BR /&gt;
I don't want to see logs from Client-B and Client-C.&lt;/P&gt;

&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2016 15:27:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-store-or-index-data-from-multiple-clients-that-have/m-p/224162#M43882</guid>
      <dc:creator>makincerdas</dc:creator>
      <dc:date>2016-09-28T15:27:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to store or index data from multiple clients that have multiple servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-store-or-index-data-from-multiple-clients-that-have/m-p/224163#M43883</link>
      <description>&lt;P&gt;With Splunk, each server would be identified by the server name, so if you wanted to look at just one server, then you simply enter a search that only looks at that one server.&lt;BR /&gt;
With Splunk, you can create groups of servers a number of different ways to isolate your Client groups, and search on all groups, or just one group.&lt;BR /&gt;
Once set up, all logs from all servers are collected in one location in pretty much real time, so there is no need to log into each server.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2016 16:39:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-store-or-index-data-from-multiple-clients-that-have/m-p/224163#M43883</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2016-09-28T16:39:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to store or index data from multiple clients that have multiple servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-store-or-index-data-from-multiple-clients-that-have/m-p/224164#M43884</link>
      <description>&lt;P&gt;lukejadamec, &lt;/P&gt;

&lt;P&gt;I appreciate your quick response.&lt;BR /&gt;
Can you provide one example on how to create groups of servers on Splunk?&lt;BR /&gt;
Is this done on Indexer or on Forwarder?&lt;BR /&gt;
Where can I find document about creating groups on Splunk to isolate Client groups?&lt;/P&gt;

&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2016 17:06:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-store-or-index-data-from-multiple-clients-that-have/m-p/224164#M43884</guid>
      <dc:creator>makincerdas</dc:creator>
      <dc:date>2016-09-28T17:06:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to store or index data from multiple clients that have multiple servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-store-or-index-data-from-multiple-clients-that-have/m-p/224165#M43885</link>
      <description>&lt;P&gt;Actually, @ddrillic posted an example for doing this with the Calculated Fields UI yesterday in this answer: &lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/453481/splunk-calculated-fields.html#answer-453486"&gt;https://answers.splunk.com/answers/453481/splunk-calculated-fields.html#answer-453486&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Another way to do it would be give each cluster it's own index, or set of indexes.&lt;/P&gt;

&lt;P&gt;The Calculated Field solution would be a search time solution configured on the search head.  The index solution would separate things at index time and is configured on the forwarder that is monitoring the logs.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2016 17:49:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-store-or-index-data-from-multiple-clients-that-have/m-p/224165#M43885</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2016-09-28T17:49:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to store or index data from multiple clients that have multiple servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-store-or-index-data-from-multiple-clients-that-have/m-p/224166#M43886</link>
      <description>&lt;P&gt;Is this below what you mean by...Give each cluster it's own index, or set of indexes?&lt;/P&gt;

&lt;P&gt;Client A : Servers for Client A has forwarder set to Cluster-Indexer-A (let's say 2 Indexer machines)&lt;BR /&gt;
Client B : Servers for Client B has forwarder set to Cluster-Indexer-B (let's say 2 Indexer machines)&lt;BR /&gt;
Client C : Servers for Client C has forwarder set to Cluster-Indexer-C (let's say 2 Indexer machines)&lt;/P&gt;

&lt;P&gt;So when issue happens to Client, I can do the search, the search head will go directly to Cluster-Indexer-A.&lt;BR /&gt;
I see similiar approach on this link:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/8226/selective-indexing-and-forwarding-based-on-source.html"&gt;https://answers.splunk.com/answers/8226/selective-indexing-and-forwarding-based-on-source.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Am I understanding correctly here?&lt;/P&gt;

&lt;P&gt;Can I still have ONE big cluster of Index consists of Indexer-A, Indexer-B, Indexer-C (total 6 machines)?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2016 13:55:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-store-or-index-data-from-multiple-clients-that-have/m-p/224166#M43886</guid>
      <dc:creator>makincerdas</dc:creator>
      <dc:date>2016-09-29T13:55:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to store or index data from multiple clients that have multiple servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-store-or-index-data-from-multiple-clients-that-have/m-p/224167#M43887</link>
      <description>&lt;P&gt;Basically yes.  I do this exact thing.  Here are some examples of how you would construct the searches you mentioned if each cluster was given it's own index.  Note: the index names cannot include dashes, so I changed them to underscores.   FYI, these are the exact search string that you would enter into Splunk:&lt;BR /&gt;
To search all logs on all servers from Cluster-Indexer-A:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=Cluster_Indexer_A
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;To search all logs on all servers from all Clusters:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=Cluster_Indexer_*
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 29 Sep 2016 14:14:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-store-or-index-data-from-multiple-clients-that-have/m-p/224167#M43887</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2016-09-29T14:14:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to store or index data from multiple clients that have multiple servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-store-or-index-data-from-multiple-clients-that-have/m-p/224168#M43888</link>
      <description>&lt;P&gt;Which high level diagram is suitable for this kind implementation? (give each cluster it's own index, or set of indexes)&lt;/P&gt;

&lt;P&gt;UF : Universal Forwarder&lt;BR /&gt;
IDX : Indexer&lt;BR /&gt;
LB : Load Balancer&lt;BR /&gt;
SH : Search Head&lt;/P&gt;

&lt;P&gt;Diagram 1 (2 LB)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;A-UF---\     /---A-IDX----\
A-UF----\   /----A-IDX-----\

B-UF------L----- B-IDX-------L------S
B-UF------B----- B-IDX-------B------H

C-UF----/   \----C-IDX-----/
C-UF---/     \---C-IDX----/
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Diagram 2 (4 LB)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;A-UF---\     /---A-IDX-----L---\
A-UF----\   /----A-IDX-----B----\

B-UF------L------B-IDX-----L------S
B-UF------B------B-IDX-----B------H

C-UF----/   \----C-IDX-----L----/
C-UF---/     \---C-IDX-----B---/
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Diagram 3 (4 LB)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;A-UF------L------A-IDX---\
A-UF------B------A-IDX----\
                           \
B-UF------L------B-IDX-----L------S
B-UF------B------B-IDX-----B------H
                           /
C-UF------L------C-IDX----/
C-UF------B------C-IDX---/
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Diagram 4 (6 LB)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;A-UF-----L-----A-IDX-----L---\
A-UF-----B-----A-IDX-----B----\
                               \
B-UF-----L-----B-IDX-----L------S
B-UF-----B-----B-IDX-----B------H
                               /
C-UF-----L-----C-IDX-----L----/
C-UF-----B-----C-IDX-----B---/
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 30 Sep 2016 12:46:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-store-or-index-data-from-multiple-clients-that-have/m-p/224168#M43888</guid>
      <dc:creator>makincerdas</dc:creator>
      <dc:date>2016-09-30T12:46:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to store or index data from multiple clients that have multiple servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-store-or-index-data-from-multiple-clients-that-have/m-p/224169#M43889</link>
      <description>&lt;P&gt;Well, it really depends on the scale.  I can do this with one indexer and no forwarders monitoring a very complex system with different groups of logs going to different indexes on one piece of powerful hardware, or I can add load balancers, multiple indexers, and separate search heads for large enterprise deployments. &lt;BR /&gt;
What you will need will depend on network speed, log volume, server capability, number of users accessing search, and the like.&lt;BR /&gt;
From what you have described, I could have all servers report to one indexer that also serves as a search head, provided the network speed was good, the volume was within tolerance, and the indexer hardware was good enough to provide both indexing and searching capability.&lt;BR /&gt;
You should really take this up with "Splunk the Company" to plan a large deployment.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2016 23:41:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-store-or-index-data-from-multiple-clients-that-have/m-p/224169#M43889</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2016-09-30T23:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to store or index data from multiple clients that have multiple servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-store-or-index-data-from-multiple-clients-that-have/m-p/224170#M43890</link>
      <description>&lt;P&gt;Also, this is Splunk Answers, not a chat line.  You ask a question, get an answer, accept the answer, ask a new question, etc....&lt;BR /&gt;
Let's try to keep Splunk Answers in focus and on point.  It makes it more valuable in the long run for everyone.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2016 23:51:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-store-or-index-data-from-multiple-clients-that-have/m-p/224170#M43890</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2016-09-30T23:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to store or index data from multiple clients that have multiple servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-store-or-index-data-from-multiple-clients-that-have/m-p/224171#M43891</link>
      <description>&lt;P&gt;Thank you @lukejadamec for your help.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 14:18:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-store-or-index-data-from-multiple-clients-that-have/m-p/224171#M43891</guid>
      <dc:creator>makincerdas</dc:creator>
      <dc:date>2016-10-03T14:18:35Z</dc:date>
    </item>
  </channel>
</rss>

