<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checklist before installing Splunk in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Checklist-before-installing-Splunk/m-p/388725#M5291</link>
    <description>&lt;P&gt;We are having Splunk version 7.1.2 &lt;/P&gt;</description>
    <pubDate>Wed, 29 May 2019 08:01:21 GMT</pubDate>
    <dc:creator>spectrum2035</dc:creator>
    <dc:date>2019-05-29T08:01:21Z</dc:date>
    <item>
      <title>Checklist before installing Splunk?</title>
      <link>https://community.splunk.com/t5/Installation/Checklist-before-installing-Splunk/m-p/388720#M5286</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;We are planning to put new instance of Splunk which has Search Head clusters Indexer clusters. All the machines are running on RHEL 7.2. Do you have any checklist which I can go through before installing Splunk?&lt;/P&gt;
&lt;P&gt;Like connectivity between servers, ulimits, permissions etc.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 23:51:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Checklist-before-installing-Splunk/m-p/388720#M5286</guid>
      <dc:creator>spectrum2035</dc:creator>
      <dc:date>2020-06-11T23:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: Checklist before installing Splunk</title>
      <link>https://community.splunk.com/t5/Installation/Checklist-before-installing-Splunk/m-p/388721#M5287</link>
      <description>&lt;P&gt;What version of Splunk are you planning on installing? &lt;/P&gt;

&lt;P&gt;There are some general things like you mentioned ulimits, tph, create splunk account etc.&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2019 15:54:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Checklist-before-installing-Splunk/m-p/388721#M5287</guid>
      <dc:creator>uhaq</dc:creator>
      <dc:date>2019-05-28T15:54:01Z</dc:date>
    </item>
    <item>
      <title>Re: Checklist before installing Splunk</title>
      <link>https://community.splunk.com/t5/Installation/Checklist-before-installing-Splunk/m-p/388722#M5288</link>
      <description>&lt;P&gt;Are you creating a brand-new Splunk installation with SH cluster and indexer cluster?   Or are you adding a Splunk instance to an existing cluster?&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2019 16:04:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Checklist-before-installing-Splunk/m-p/388722#M5288</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-05-28T16:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: Checklist before installing Splunk</title>
      <link>https://community.splunk.com/t5/Installation/Checklist-before-installing-Splunk/m-p/388723#M5289</link>
      <description>&lt;P&gt;Plan your architecture based on the requirement. While determining the same you need to take into consideration the below points.&lt;BR /&gt;
• The overall goal of the deployment&lt;BR /&gt;
• Key users, their goals and use cases.&lt;BR /&gt;
• Expected daily data ingestion.&lt;BR /&gt;
• Data sources.&lt;BR /&gt;
• Data retention.&lt;BR /&gt;
• List of user access roles required.&lt;BR /&gt;
Taking the above points into consideration would help you in architecting the Splunk deployment better.&lt;/P&gt;

&lt;P&gt;Once the hardware is in place, you may follow the below mentioned best practices while building a Splunk instance.&lt;BR /&gt;
• Do not run Splunk as super-user. e.g. root in *nix and administrator in Windows.&lt;BR /&gt;
• Create a user account that is used to run Splunk –&lt;BR /&gt;
For input, Splunk must be able to access data sources, On *NIX, /var/log is not typically open to non-root accounts, On *NIX, non-root accounts cannot access ports &amp;lt; 1024&lt;BR /&gt;
On Windows use a domain account if Splunk must connect to other servers otherwise, use a local machine account that can run services make sure the Splunk account can access scripts used for inputs and alerts.&lt;BR /&gt;
• Use a time synchronization service such as NTP. It is imperative that your Splunk indexer and production servers have standardized time configuration. Clock skew between hosts can affect search results.&lt;BR /&gt;
Linux settings recommendations.&lt;BR /&gt;
• Increase ulimit settings –These parameters need to be increased to allow for many buckets/forwarders/users&lt;BR /&gt;
Please refer to the below document link:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/ulimitErrors"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/ulimitErrors&lt;/A&gt;&lt;BR /&gt;
• Turn Transparent Huge Pages (THP) off on Splunk Enterprise servers&lt;BR /&gt;
Please refer the below link for details.&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/ReleaseNotes/SplunkandTHP"&gt;https://docs.splunk.com/Documentation/Splunk/latest/ReleaseNotes/SplunkandTHP&lt;/A&gt;&lt;BR /&gt;
Post this you can follow the Splunk installation guide and install the downloaded rpm.&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2019 17:40:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Checklist-before-installing-Splunk/m-p/388723#M5289</guid>
      <dc:creator>sayaksplunk</dc:creator>
      <dc:date>2019-05-28T17:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: Checklist before installing Splunk</title>
      <link>https://community.splunk.com/t5/Installation/Checklist-before-installing-Splunk/m-p/388724#M5290</link>
      <description>&lt;P&gt;We have an existing INDX and SHC with Splunk version 7.1.2 and adding more servers in to the cluster.&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2019 08:00:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Checklist-before-installing-Splunk/m-p/388724#M5290</guid>
      <dc:creator>spectrum2035</dc:creator>
      <dc:date>2019-05-29T08:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: Checklist before installing Splunk</title>
      <link>https://community.splunk.com/t5/Installation/Checklist-before-installing-Splunk/m-p/388725#M5291</link>
      <description>&lt;P&gt;We are having Splunk version 7.1.2 &lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2019 08:01:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Checklist-before-installing-Splunk/m-p/388725#M5291</guid>
      <dc:creator>spectrum2035</dc:creator>
      <dc:date>2019-05-29T08:01:21Z</dc:date>
    </item>
  </channel>
</rss>

