Deployment Architecture

How to sync data between two splunk servers

sureshsala
Explorer

I have few questions regarding splunk server data.
1. where does data is stored in splunk server, I am using universal forwarder to send the data to splunk.
2. How can i delete the data based on hostname. I want to delete all data based on the hostname
3. How can i sync the data between two splunk servers.

0 Karma

woodcock
Esteemed Legend

1: On your indexers, check here:

$SPLUNK_HOME/etc/system/{default|local}/indexes.conf

2: As far as hiding events from all further searches, like this:

My Search Details Here host=MyHostToDelete | delete

3: You can set up an indexer cluster with help here:

http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Clusterdeploymentoverview
http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Aboutclusters
0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...