<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Trail in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Splunk-Trail/m-p/336689#M8448</link>
    <description>&lt;P&gt;hi @niketnilay,&lt;/P&gt;

&lt;P&gt;thanks for sharing useful information.&lt;BR /&gt;
I am looking exactly the same.&lt;/P&gt;</description>
    <pubDate>Wed, 02 May 2018 08:45:03 GMT</pubDate>
    <dc:creator>rashid47010</dc:creator>
    <dc:date>2018-05-02T08:45:03Z</dc:date>
    <item>
      <title>Splunk Trail</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Trail/m-p/336685#M8444</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;

&lt;P&gt;I want to install splunk trail version. I have multiple Domain Controllers, File Servers, Exchange Server, Firewalls.&lt;BR /&gt;
the idea is to present splunk capabilities.&lt;/P&gt;

&lt;P&gt;Please tell me:&lt;BR /&gt;
1-Trial license is 500 MB/per day so what should be my strategy( how many indexers, search heads and Forwarders I can configure)&lt;BR /&gt;
2- estimate space required for each data source, for example, for DC how many events can be indexed.&lt;BR /&gt;
3- what should be my architecture strategy. &lt;BR /&gt;
4- How can I drop windows events at universal forwarder or Index level.&lt;BR /&gt;
5- How can I filter network events( should I do this at network device it self .. OR i can drop events at index level.&lt;/P&gt;</description>
      <pubDate>Sun, 15 Apr 2018 18:29:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Trail/m-p/336685#M8444</guid>
      <dc:creator>rashid47010</dc:creator>
      <dc:date>2018-04-15T18:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Trail</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Trail/m-p/336686#M8445</link>
      <description>&lt;P&gt;@rashid47010, For point 1 and 3: Refer to Splunk Validated Architectures &lt;A href="https://www.splunk.com/pdfs/white-papers/splunk-validated-architectures.pdf"&gt;whitepaper&lt;/A&gt; and &lt;A href="http://conf.splunk.com/sessions/2017-sessions.html#search=Splunk%20Validated%20Architectures&amp;amp;"&gt;.conf 2017 Session&lt;/A&gt; for the same. &lt;/P&gt;

&lt;P&gt;For Point 2: If you have Splunk Admin/Architect provide them with the devices details, volume of data per day/per week and data growth, retention requirement etc. If not reach out to Splunk Sales folks (Sales Rep or Sales Engineer) who might be closely tied to you/your location or else get the help from &lt;A href="https://partners.splunk.com/locator/search?f0=Type+Of+Partner&amp;amp;f0v0=Professional+Services"&gt;Professional Services&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;For point 4: dropping event based on your input data, some data can be filtered via Universal Forwarder using blacklist option ( if they are supported ) in the inputs.conf.&lt;/P&gt;

&lt;P&gt;If not you can use &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues"&gt;nullQueue&lt;/A&gt; to filter data from getting indexed. Other option would be to use &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/AdvancedDev/ScriptedInputsIntro"&gt;Scripted Input&lt;/A&gt; to Splunk and have your Script drop the unwanted data from being indexed.&lt;/P&gt;</description>
      <pubDate>Sun, 15 Apr 2018 22:31:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Trail/m-p/336686#M8445</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-04-15T22:31:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Trail</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Trail/m-p/336687#M8446</link>
      <description>&lt;P&gt;For #1-3: If your desire is to demonstrate/examine Splunk capabilities, then my advice to you is not to stand up your own test infrastructure; you would be MUCH better off simply firing up an ES or ITSI sandbox which has your sourcetypes already coming in.&lt;/P&gt;

&lt;P&gt;For #4, there is a github app for cutting down on Windows event sizes that should be easily found with any search engine.&lt;/P&gt;

&lt;P&gt;For #5, in general, don't weigh down your indexers doing filter work that can be done any place else.&lt;/P&gt;</description>
      <pubDate>Sun, 15 Apr 2018 22:55:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Trail/m-p/336687#M8446</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-04-15T22:55:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Trail</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Trail/m-p/336688#M8447</link>
      <description>&lt;P&gt;Hey@rashid47010,&lt;/P&gt;

&lt;P&gt;There are certain limitation for trial license such as clustering and all cannot be done.&lt;BR /&gt;
Refer this doc for limitations:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.3/Admin/MoreaboutSplunkFree"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.3/Admin/MoreaboutSplunkFree&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Let me know if this helps!!!&lt;/P&gt;</description>
      <pubDate>Mon, 16 Apr 2018 06:07:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Trail/m-p/336688#M8447</guid>
      <dc:creator>deepashri_123</dc:creator>
      <dc:date>2018-04-16T06:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Trail</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Trail/m-p/336689#M8448</link>
      <description>&lt;P&gt;hi @niketnilay,&lt;/P&gt;

&lt;P&gt;thanks for sharing useful information.&lt;BR /&gt;
I am looking exactly the same.&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2018 08:45:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Trail/m-p/336689#M8448</guid>
      <dc:creator>rashid47010</dc:creator>
      <dc:date>2018-05-02T08:45:03Z</dc:date>
    </item>
  </channel>
</rss>

