All Apps and Add-ons

Has anyone had issues using the Splunk App for CEF in a Splunk 6.x environment with search head and indexer clustering?

brian1_tate
Path Finder

Anyone have any issues with using the CEF app and have search head clustering along with indexer clusters?

I would think this is more common with these types of deployments. I was informed that the CEF app is not 'search head cluster compatible' yet that sounds odd with larger deployments. I would prefer to use this method rather than edit the outputs.conf and so on. Anyone have any comments with what they have done or ran into this?

Thanks!

0 Karma

LukeMurphey
Champion

Version 2.0 of the CEF now supports Search Head Clustering (see the release notes).

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...