Deployment Architecture

Where is the Distributed Management Console's index stored, and what storage is necessary for each monitored instance?

juliendomart
New Member

HI Splunkers,

I want to try the Splunk Distributed Management Console on a distributed Splunk enterprise infrastructure and I have two questions about DMC use.

We want to install the DMC on a dedicated search head and we didn't find any information where Splunk will store the DMC's index (on our search head or indexer )?

Second point, what storage is necessary for each kind of monitored server and what is the retention time of DMC information?

Thanks for these clarifications

0 Karma

sduchene_splunk
Splunk Employee
Splunk Employee

Hello,
The DMC doesn't store any data, as stated here every Splunk instance has to forward internal index as well as introspection index to the indexers :
http://docs.splunk.com/Documentation/Splunk/6.2.0/Admin/ConfiguretheMonitoringConsole

The DMC is searching on those logs, stored on the indexers.

0 Karma

stephanefotso
Motivator
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...