Deployment Architecture

Deployment Architecture
Community Activity
enmanu
I currently have 4 indexers. I have a new mount drive that I am trying to send Splunk cold data to. [volume:cold] co...
by enmanu New Member in Deployment Architecture 11-08-2018
0 1
0
1
Robbie1194
Hi guys, I've just set up a new SHC with the label shcluster1. Each search head and the deployer have this label. I...
by Robbie1194 Communicator in Deployment Architecture 11-08-2018
0 2
0
2
arkadyz1
From the documentation (Getting Data In, v6.2.1): Restart Splunk for your changes to take effect Changes to configu...
by arkadyz1 Builder in Deployment Architecture 11-07-2018
0 3
0
3
jiaqya
How do I reduce an index size in a way so that I can delete older data from the index to make the size of the index c...
by jiaqya Builder in Deployment Architecture 11-07-2018
0 4
0
4
ddrillic
The architecting Splunk 7.1 Enterprise Deployments class empathizes that setting annotate_punct = false in props.conf...
by ddrillic Ultra Champion in Deployment Architecture 11-07-2018
1 2
1
2
ischoenmaker
With scaling infrastructure and the requirement to bind machines to a pool instead of using catch-all (slaves = *) we...
by ischoenmaker Explorer in Deployment Architecture 11-07-2018
0 0
0
0
ankitcharolia09
I see warning message in splunk master node. "Audit event generator: Now skipping indexing of internal audit events,...
by ankitcharolia09 Engager in Deployment Architecture 11-06-2018
5 5
5
5
zbowman
Have never had this error before, but today we had an alert that 100 buckets were created and it appears to be a lot ...
by zbowman New Member in Deployment Architecture 11-06-2018
0 0
0
0
bjarnedein
Hi Guys, Maybe a bit of a challenging question, but how "intelligent" is the Splunk clusters really? Say you have a...
by bjarnedein Explorer in Deployment Architecture 11-06-2018
0 4
0
4
stsamson005
We have notice the following behaviour when using a domain to hit a search head If we hit the search head directly u...
by stsamson005 Engager in Deployment Architecture 11-05-2018
0 0
0
0
anoopdi
Under Forwarder Management UI --> Apps tab. I see all the apps there but none of them show the number of clients that...
by anoopdi Path Finder in Deployment Architecture 11-05-2018
0 4
0
4
central1
I have a requirement to send certain filtered log events on to a 3rd party in addition to indexing the events locally...
by central1 Explorer in Deployment Architecture 11-04-2018
0 4
0
4
daniel333
All, I placed Splunk_TA_stream on a bunch of boxes and now the search head it's hitting is getting murdered perform...
by daniel333 Builder in Deployment Architecture 11-02-2018
0 1
0
1
Marcia_Piccione
We have a client that requires at least some of the following for Access-Control-Allow-Headers: Access-Control-All...
by Marcia_Piccione Engager in Deployment Architecture 11-02-2018
1 1
1
1
joesrepsol
Hello! Looking to do some patch monitoring on our *nix boxes and find the "rpm -qa --list" command extremely useful....
by joesrepsol Path Finder in Deployment Architecture 11-02-2018
0 2
0
2
drodman29
I have a clob field that I don't want to index in full, is there a way to manipulate a splunkdb input before the cont...
by drodman29 Path Finder in Deployment Architecture 11-02-2018
0 0
0
0
briancronrath
We use 12 indexers in a cluster. They have the same exact hardware and install dates on all of them. However, there a...
by briancronrath Contributor in Deployment Architecture 11-01-2018
0 2
0
2
brianhunter99
It's not the current version, but due to multiple reasons in my environment we are still running Splunk Enterprise r6...
by brianhunter99 New Member in Deployment Architecture 11-01-2018
0 0
0
0
stcrispan
In serverclass.conf... I'm creating different classes, for deployment. I've inherited this setup, and the previous ...
by stcrispan Communicator in Deployment Architecture 11-01-2018
2 5
2
5
coreyf311
I created a barebones app on the deployer, copied it to shcluster/apps directory and pushed it to the 6 nodes of our ...
by coreyf311 Path Finder in Deployment Architecture 11-01-2018
0 5
0
5
daniel333
all, I am running this search to collect exceptions by host. I am bucketing into 1min intervals. However when I go ...
by daniel333 Builder in Deployment Architecture 10-31-2018
0 0
0
0
davietch
Hi, I want to limit the number of IP resolved by the "| lookup dnslookup" command. Is there a way to do it? EDIT: ...
by davietch Path Finder in Deployment Architecture 10-31-2018
0 6
0
6
EmEdwards
I know how to create an app from the GUI of Splunk. But, on a clustered environment, I believe this needs to be creat...
by EmEdwards Path Finder in Deployment Architecture 10-31-2018
1 2
1
2
koshyk
hi, We have quite a large amount of users and hence leavers/movers are common. We are aware of how to fix the orphan...
by koshyk Super Champion in Deployment Architecture 10-31-2018
0 2
0
2
thomas_porter
Let's say I have two groups of two indexers, each group in its own cluster. Can I use a single master cluster node t...
by thomas_porter Explorer in Deployment Architecture 10-31-2018
0 4
0
4
Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...