<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can anyone explain me how to on board data. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-anyone-explain-me-how-to-on-board-data/m-p/307650#M93865</link>
    <description>&lt;P&gt;Appreciate it sir for you taking time to look in to.&lt;/P&gt;</description>
    <pubDate>Sat, 14 Oct 2017 16:54:39 GMT</pubDate>
    <dc:creator>Rocky31</dc:creator>
    <dc:date>2017-10-14T16:54:39Z</dc:date>
    <item>
      <title>Can anyone explain me how to on board data.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-anyone-explain-me-how-to-on-board-data/m-p/307648#M93863</link>
      <description>&lt;P&gt;I was hired in an organization as a Splunk onboard specialist, I don't know much about onboarding data. I had gone through getting data in docs but that is not helpful to deal in real time.&lt;/P&gt;

&lt;P&gt;Our environment 325 GB/ per day&lt;BR /&gt;
7 indexers, 4 SH, 100 UF.&lt;/P&gt;

&lt;P&gt;Can anyone please share your onboarding knowledge with me.&lt;/P&gt;

&lt;P&gt;splunk learner.&lt;BR /&gt;
Rocky.&lt;/P&gt;</description>
      <pubDate>Sat, 14 Oct 2017 15:21:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-anyone-explain-me-how-to-on-board-data/m-p/307648#M93863</guid>
      <dc:creator>Rocky31</dc:creator>
      <dc:date>2017-10-14T15:21:49Z</dc:date>
    </item>
    <item>
      <title>Re: Can anyone explain me how to on board data.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-anyone-explain-me-how-to-on-board-data/m-p/307649#M93864</link>
      <description>&lt;P&gt;Hi  Rocky31,&lt;BR /&gt;
at first I suggest to quickly start with Splunk free training ( &lt;A href="https://www.splunk.com/view/SP-CAAAPX9"&gt;https://www.splunk.com/view/SP-CAAAPX9&lt;/A&gt; and &lt;A href="https://www.splunk.com/view/SP-CAAAHSM"&gt;https://www.splunk.com/view/SP-CAAAHSM&lt;/A&gt; ) and then partecipate to a splunk certification plan, at least as Administrator, better as Architect.&lt;/P&gt;

&lt;P&gt;Anyway at first you should define your perimeter and monitoring needs (logs files, scripts, wineventlogs, etc... to take for monitoring) to understand and configure your architecture.&lt;BR /&gt;
In this way you know which logs are you waiting for and how to prepare your Splunk distributed architecture,&lt;/P&gt;

&lt;P&gt;Then you have to define which service level you need, in other words do you need clustered indexers and/or clustered search heads?&lt;BR /&gt;
So you'll have a configured Splunk distributed search architetcture that can index and search logs.&lt;/P&gt;

&lt;P&gt;Then if you have Forwarders, you need to use a dedicated Deployment Server to deploy configurations to Forwarders (for more than 50 forwarders must be a dedicated server).&lt;BR /&gt;
Configurations are in apps called Technical Addons (TAs) that contain information about the indexers to send data (outputs.conf) and objects to monitor (files, scripts, wineventlogs, etc...).&lt;BR /&gt;
Remember that Deployment Server is the only configuration that must be done locally on forwarders.&lt;/P&gt;

&lt;P&gt;When you have clear ideas about monitoring requirements you can start to prepare your TAs:&lt;BR /&gt;
at first configure a TA containing only outputs.conf to correctly address your Forwarders to send logs to the Indexers.&lt;/P&gt;

&lt;P&gt;You can check the connecting Forwarders runnning a simple search on Search Heads (index=_internal | stats count by host) and verify if all your Forwarders are connected.&lt;/P&gt;

&lt;P&gt;Then prepare your TAs to ingest data for the required monitoring.&lt;BR /&gt;
When you're sure to index the correct data you can start to prepare your searches to display the situations to monitor (errors, health status, etc...).&lt;/P&gt;

&lt;P&gt;I hope to be useful for you, anyway first thing is training, but in addition to read answers.splunk.com is a good idea to understand behaviour.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 14 Oct 2017 15:49:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-anyone-explain-me-how-to-on-board-data/m-p/307649#M93864</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-10-14T15:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: Can anyone explain me how to on board data.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-anyone-explain-me-how-to-on-board-data/m-p/307650#M93865</link>
      <description>&lt;P&gt;Appreciate it sir for you taking time to look in to.&lt;/P&gt;</description>
      <pubDate>Sat, 14 Oct 2017 16:54:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-anyone-explain-me-how-to-on-board-data/m-p/307650#M93865</guid>
      <dc:creator>Rocky31</dc:creator>
      <dc:date>2017-10-14T16:54:39Z</dc:date>
    </item>
    <item>
      <title>Re: Can anyone explain me how to on board data.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-anyone-explain-me-how-to-on-board-data/m-p/307651#M93866</link>
      <description>&lt;P&gt;I have another question, why i don't find output.conf file in splunkforwarder in free splunk on my local instance&lt;/P&gt;

&lt;P&gt;location:&lt;/P&gt;

&lt;P&gt;MacBook-Pro:local RRRR$ pwd&lt;BR /&gt;
/Applications/splunkforwarder/etc/system/local&lt;/P&gt;</description>
      <pubDate>Sat, 14 Oct 2017 18:05:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-anyone-explain-me-how-to-on-board-data/m-p/307651#M93866</guid>
      <dc:creator>Rocky31</dc:creator>
      <dc:date>2017-10-14T18:05:40Z</dc:date>
    </item>
    <item>
      <title>Re: Can anyone explain me how to on board data.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-anyone-explain-me-how-to-on-board-data/m-p/307652#M93867</link>
      <description>&lt;P&gt;Hi Rocky31,&lt;BR /&gt;
Because outputs.conf is created when you run the following command&lt;BR /&gt;
./splunk add forward-server :&lt;BR /&gt;
see &lt;A href="http://docs.splunk.com/Documentation/Forwarder/7.0.0/Forwarder/Configuretheuniversalforwarder"&gt;http://docs.splunk.com/Documentation/Forwarder/7.0.0/Forwarder/Configuretheuniversalforwarder&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I suggest to put outputs.con in a dedicated TA to manage using a Deployment Server not in $SPLUNK_HOME/etc/system/local&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Sun, 15 Oct 2017 08:15:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-anyone-explain-me-how-to-on-board-data/m-p/307652#M93867</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-10-15T08:15:09Z</dc:date>
    </item>
  </channel>
</rss>

