Deployment Architecture

How to sync data between two splunk servers

sureshsala
Explorer

I have few questions regarding splunk server data.
1. where does data is stored in splunk server, I am using universal forwarder to send the data to splunk.
2. How can i delete the data based on hostname. I want to delete all data based on the hostname
3. How can i sync the data between two splunk servers.

0 Karma

woodcock
Esteemed Legend

1: On your indexers, check here:

$SPLUNK_HOME/etc/system/{default|local}/indexes.conf

2: As far as hiding events from all further searches, like this:

My Search Details Here host=MyHostToDelete | delete

3: You can set up an indexer cluster with help here:

http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Clusterdeploymentoverview
http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Aboutclusters
0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...