<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Questions on best practices for a new Splunk environment in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Questions-on-best-practices-for-a-new-Splunk-environment/m-p/313162#M5744</link>
    <description>&lt;P&gt;Thanks a lot once again. for Question 5: Under settings &amp;gt; Data &amp;gt; Forwarding $ Receiving &amp;gt; Forward data &amp;gt; Configure forwarding &amp;gt; I do see names of my indexers:9997 (splunk03:9997 &amp;amp; splunk04:9997) status as enabled which means it is forwarding I guess. Sorry but I did not get your statement "unless the inputs have indexAndForward enabled" how do I check this index &amp;amp; forward?&lt;/P&gt;</description>
    <pubDate>Wed, 30 Aug 2017 17:40:58 GMT</pubDate>
    <dc:creator>hrithiktej</dc:creator>
    <dc:date>2017-08-30T17:40:58Z</dc:date>
    <item>
      <title>Questions on best practices for a new Splunk environment</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Questions-on-best-practices-for-a-new-Splunk-environment/m-p/313158#M5740</link>
      <description>&lt;P&gt;Sorry for too many questions &lt;/P&gt;

&lt;P&gt;This is our environment&lt;/P&gt;

&lt;P&gt;6 Splunk servers&lt;/P&gt;

&lt;P&gt;1) splunk01 – Ad HOC Search head used for standalone searches&lt;/P&gt;

&lt;P&gt;47.14 GB Physical Memory, 10 CPU Cores&lt;/P&gt;

&lt;P&gt;2) splunk02 – Enterprise Security Search Head has Enterprise Security app installed on it.&lt;/P&gt;

&lt;P&gt;125.75 GB Physical Memory, 24 CPU Cores&lt;/P&gt;

&lt;P&gt;3) splunk03 – Indexer – Syslog plus Indexer server&lt;/P&gt;

&lt;P&gt;62.75 GB Physical Memory, 24 CPU Cores&lt;/P&gt;

&lt;P&gt;4) splunk04 – Indexer – Syslog plus Indexer server&lt;/P&gt;

&lt;P&gt;62.75 GB Physical Memory, 24 CPU Cores&lt;/P&gt;

&lt;P&gt;Below two Splunk servers are on a host that has several other VMs hosted on it.&lt;/P&gt;

&lt;P&gt;5) splunk05 – License Master plus Indexer cluster master&lt;/P&gt;

&lt;P&gt;7.64 GB Physical Memory, 4 CPU Cores&lt;/P&gt;

&lt;P&gt;6) splunk06 – Deployment Server&lt;/P&gt;

&lt;P&gt;3.7 GB Physical Memory, 2 CPU Cores&lt;/P&gt;

&lt;P&gt;Question 1) Our indexers 3&amp;amp;4 are also Syslog servers with HD of 5tb each is it a best practice to have Indexers and Syslog servers on the same box?&lt;/P&gt;

&lt;P&gt;Question 2) Our License master with its current RAM and CPU config as stated above is it enough to be a License master?&lt;/P&gt;

&lt;P&gt;Question 3) Since our Syslog and indexer reside on the same box does that mean our HFs don't play any role in forwarding data?&lt;/P&gt;

&lt;P&gt;Question 4) Can we install DMC on our license master?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 15:03:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Questions-on-best-practices-for-a-new-Splunk-environment/m-p/313158#M5740</guid>
      <dc:creator>hrithiktej</dc:creator>
      <dc:date>2017-08-30T15:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: Questions on best practices for a new Splunk environment</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Questions-on-best-practices-for-a-new-Splunk-environment/m-p/313159#M5741</link>
      <description>&lt;P&gt;Question 1) Our indexers 3&amp;amp;4 are also Syslog servers with HD of 5tb each is it a best practice to have Indexers and Syslog servers on the same box?&lt;BR /&gt;&lt;BR /&gt;
Answer 1) No, not really. You can do it but then you're going to decrease the available incoming network ports, add extra load, create a maintenance / patching/ upgrade nightmare, etc.&lt;/P&gt;

&lt;P&gt;Question 2) Our License master with its current RAM and CPU config as stated above is it enough to be a License master?&lt;BR /&gt;
Answer 2) Yes its enough&lt;/P&gt;

&lt;P&gt;Question 3) Since our Syslog and indexer reside on the same box does that mean our HFs don't play any role in forwarding data?&lt;BR /&gt;
Answer 3) there are very few use cases where HFs are needed.  You can usually use a UF instead of HF for just about everything.  Syslog will not address getting windows event logs into splunk for example... however a UF will.  &lt;/P&gt;

&lt;P&gt;Question 4) Can we install DMC on our license master?&lt;BR /&gt;
Answer 4) &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.2/DMC/WheretohostDMC"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.2/DMC/WheretohostDMC&lt;/A&gt;&lt;BR /&gt;
It should go on your master node according to the documentation, which in your case, is the same as the license master.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 15:25:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Questions-on-best-practices-for-a-new-Splunk-environment/m-p/313159#M5741</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-08-30T15:25:45Z</dc:date>
    </item>
    <item>
      <title>Re: Questions on best practices for a new Splunk environment</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Questions-on-best-practices-for-a-new-Splunk-environment/m-p/313160#M5742</link>
      <description>&lt;P&gt;Thank you very much for your quick help. Sorry I am new to splunk&lt;/P&gt;

&lt;P&gt;Can you elaborate on Question no. 1 I ask again because we have a lot of performance issues our searches are slow.&lt;/P&gt;

&lt;P&gt;&amp;amp; Question 3 I read the doc thanks and I think below is our scenario&lt;/P&gt;

&lt;P&gt;Distributed mode Yes&lt;BR /&gt;
Indexer clustering yes&lt;BR /&gt;
Search head clustering  Not relevant&lt;BR /&gt;
Monitoring Console options&lt;BR /&gt;
The master node. If preferred, you can instead run the Monitoring Console on a dedicated search head not used for other purposes. So does this mean I should install DMC on our master server?&lt;/P&gt;

&lt;P&gt;one more question&lt;BR /&gt;
Question 5)&lt;BR /&gt;
All our Router, Switches, FWs, forward data directly to our Syslog servers which are nothing but our indexers 3 &amp;amp; 4 but our estreamer i.e. Cisco IPS/Firepower manager forwards data to Splunk 02 server i.e. our Enterprise Security app search head now I want to know whether Splunk 02 does the indexing of data on its own or does it forward it to indexers 3 &amp;amp;4 for indexing and then request it back during searches.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 16:29:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Questions-on-best-practices-for-a-new-Splunk-environment/m-p/313160#M5742</guid>
      <dc:creator>hrithiktej</dc:creator>
      <dc:date>2017-08-30T16:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: Questions on best practices for a new Splunk environment</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Questions-on-best-practices-for-a-new-Splunk-environment/m-p/313161#M5743</link>
      <description>&lt;P&gt;Put syslog on dedicated servers = best practice.&lt;/P&gt;

&lt;P&gt;So don't do what you're doing right now.  Build new servers for syslog and put universal forwarders on them to send the data to Splunk indexers.&lt;/P&gt;

&lt;P&gt;Question 3:  you said your cluster master is your license master... so there's no difference but yes it is supposed to be on the cluster master in your case.&lt;/P&gt;

&lt;P&gt;Question 5) you tell me the answer.  Do you have forwarding enabled on server 2? If so, then the data is forwarding to whatever you've configured unless the inputs have indexAndForward enabled.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 17:22:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Questions-on-best-practices-for-a-new-Splunk-environment/m-p/313161#M5743</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-08-30T17:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: Questions on best practices for a new Splunk environment</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Questions-on-best-practices-for-a-new-Splunk-environment/m-p/313162#M5744</link>
      <description>&lt;P&gt;Thanks a lot once again. for Question 5: Under settings &amp;gt; Data &amp;gt; Forwarding $ Receiving &amp;gt; Forward data &amp;gt; Configure forwarding &amp;gt; I do see names of my indexers:9997 (splunk03:9997 &amp;amp; splunk04:9997) status as enabled which means it is forwarding I guess. Sorry but I did not get your statement "unless the inputs have indexAndForward enabled" how do I check this index &amp;amp; forward?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 17:40:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Questions-on-best-practices-for-a-new-Splunk-environment/m-p/313162#M5744</guid>
      <dc:creator>hrithiktej</dc:creator>
      <dc:date>2017-08-30T17:40:58Z</dc:date>
    </item>
    <item>
      <title>Re: Questions on best practices for a new Splunk environment</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Questions-on-best-practices-for-a-new-Splunk-environment/m-p/313163#M5745</link>
      <description>&lt;P&gt;Index and forward is an outputs.conf setting.  I mis-spoke when I say inputs.  &lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/6.6.3/Admin/Outputsconf"&gt;https://docs.splunk.com/Documentation/Splunk/6.6.3/Admin/Outputsconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;To check if it's enabled you can use btool&lt;/P&gt;

&lt;P&gt;./splunk btool outputs list &lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 20:20:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Questions-on-best-practices-for-a-new-Splunk-environment/m-p/313163#M5745</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-08-30T20:20:12Z</dc:date>
    </item>
    <item>
      <title>Re: Questions on best practices for a new Splunk environment</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Questions-on-best-practices-for-a-new-Splunk-environment/m-p/313164#M5746</link>
      <description>&lt;P&gt;Thank you, from the below output I guess it is just forwarding to 3 &amp;amp; 4 and not doing indexing as I see index = false. &lt;/P&gt;

&lt;P&gt;[root@splunk02 bin]# ./splunk btool outputs list&lt;BR /&gt;
[indexAndForward]&lt;BR /&gt;
index = false&lt;BR /&gt;
[syslog]&lt;BR /&gt;
dropEventsOnQueueFull = -1&lt;BR /&gt;
maxEventSize = 1024&lt;BR /&gt;
priority = &amp;lt;13&amp;gt;&lt;BR /&gt;
type = udp&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
ackTimeoutOnShutdown = 30&lt;BR /&gt;
autoLBFrequency = 30&lt;BR /&gt;
blockOnCloning = true&lt;BR /&gt;
blockWarnThreshold = 100&lt;BR /&gt;
compressed = false&lt;BR /&gt;
connectionTimeout = 20&lt;BR /&gt;
defaultGroup = primary_indexers&lt;BR /&gt;
disabled = false&lt;BR /&gt;
dropClonedEventsOnQueueFull = 5&lt;BR /&gt;
dropEventsOnQueueFull = -1&lt;BR /&gt;
forceTimebasedAutoLB = false&lt;BR /&gt;
forwardedindex.0.whitelist = .*&lt;BR /&gt;
forwardedindex.1.blacklist = _.*&lt;BR /&gt;
forwardedindex.2.whitelist = (_audit|_internal|_introspection)&lt;BR /&gt;
forwardedindex.filter.disable = false&lt;BR /&gt;
heartbeatFrequency = 30&lt;BR /&gt;
indexAndForward = false&lt;BR /&gt;
maxConnectionsPerIndexer = 2&lt;BR /&gt;
maxFailuresPerInterval = 2&lt;BR /&gt;
maxQueueSize = 7MB&lt;BR /&gt;
readTimeout = 300&lt;BR /&gt;
secsInFailureInterval = 1&lt;BR /&gt;
sendCookedData = true&lt;BR /&gt;
sslQuietShutdown = false&lt;BR /&gt;
tcpSendBufSz = 0&lt;BR /&gt;
useACK = true&lt;BR /&gt;
writeTimeout = 300&lt;BR /&gt;
[tcpout:primary_indexers]&lt;BR /&gt;
server = splunk03:9997, splunk04.                                                                                                                                                                           :9997&lt;/P&gt;

&lt;P&gt;I am wondering why my prev admin chose to forward data from estreamer to splunk02 i.e. our enterprise security server rather than directly to the indexers.&lt;BR /&gt;
Is there any added benefit for forwarding estreamer to enterprise security Splunk rather than indexers first?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:35:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Questions-on-best-practices-for-a-new-Splunk-environment/m-p/313164#M5746</guid>
      <dc:creator>hrithiktej</dc:creator>
      <dc:date>2020-09-29T15:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: Questions on best practices for a new Splunk environment</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Questions-on-best-practices-for-a-new-Splunk-environment/m-p/313165#M5747</link>
      <description>&lt;P&gt;The cisco apps can be a bit special at times...  you should probably open a new question on that.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 13:16:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Questions-on-best-practices-for-a-new-Splunk-environment/m-p/313165#M5747</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-08-31T13:16:11Z</dc:date>
    </item>
    <item>
      <title>Re: Questions on best practices for a new Splunk environment</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Questions-on-best-practices-for-a-new-Splunk-environment/m-p/313166#M5748</link>
      <description>&lt;P&gt;ok, sure I will thank you very much for all your help very grateful.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 13:18:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Questions-on-best-practices-for-a-new-Splunk-environment/m-p/313166#M5748</guid>
      <dc:creator>hrithiktej</dc:creator>
      <dc:date>2017-08-31T13:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: Questions on best practices for a new Splunk environment</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Questions-on-best-practices-for-a-new-Splunk-environment/m-p/313167#M5749</link>
      <description>&lt;P&gt;Hi Many thanks for your help I have separated the syslog server from the indexers now and have installed UFs on them to forward the data, I did ran into some problems but everything is cool now and the performance in terms of searches is a lot better.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Sep 2017 17:11:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Questions-on-best-practices-for-a-new-Splunk-environment/m-p/313167#M5749</guid>
      <dc:creator>hrithiktej</dc:creator>
      <dc:date>2017-09-23T17:11:26Z</dc:date>
    </item>
  </channel>
</rss>

