| Thread Info | |||||
|---|---|---|---|---|---|
| 
        Our set up- 
  HF receives syslog (directly from firewalls, IPS, etc) and logs from UF (windows and linux machines) a...
        
         
           by 
           
                
                    
                        hkumar26
                    
                
           
             
             
               New Member
             
           
           in
           Deployment Architecture
           
           
              
               07-14-2017
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hi All, 
  Good day, would like to seek for help regarding on our universal forwarders. Some of our sources (universa...
        
         
           by 
           
                
                    
                        dantimola
                    
                
           
             
             
               Communicator
             
           
           in
           Deployment Architecture
           
           
              
               07-11-2017
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        What is the best order to perform the above? Our current Splunk environment consists of 5 clustered Indexers and 4 cl...
        
         
           by 
           
                
                    
                        lawannapage
                    
                
           
             
             
               New Member
             
           
           in
           Deployment Architecture
           
           
              
               07-12-2017
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        I have configured three files outputs.conf, transforms.conf and props.conf but still I am not getting forwarded data ...
        
         
           by 
           
                
                    
                        niveditahanuman
                    
                
           
             
             
               New Member
             
           
           in
           Deployment Architecture
           
           
              
               07-12-2017
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hi all 
  We are running Splunk on a distributed environment. We have an Index Cluster (8 nodes). Also on each system...
        
         
           by 
           
                
                    
                        Muryoutaisuu
                    
                
           
             
             
               Communicator
             
           
           in
           Deployment Architecture
           
           
              
               07-10-2017
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hi All, Currently we are facing an issue while performing a search against a particular index and found it was due to...
        
         
           by 
           
                
                    
                        Hemnaath
                    
                
           
             
             
               Motivator
             
           
           in
           Deployment Architecture
           
           
              
               07-10-2017
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Do we need to restart Deployment server if we make any changes in Splunk\etc\apps\local\inputs.conf(xyz) and \Splunk\...
        
         
           by 
           
                
                    
                        rangineniarunku
                    
                
           
             
             
               Explorer
             
           
           in
           Deployment Architecture
           
           
              
               07-11-2017
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hello, 
  We are running 6.3.3 with search head clustering and 4 search heads in the cluster. Some times users compla...
        
         
           by 
           
                
                    
                        sim_tcr
                    
                
           
             
             
               Communicator
             
           
           in
           Deployment Architecture
           
           
              
               07-11-2017
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hi guys,  
  I've been been given 2 tasks with regards to our Splunk forwarders.  
  1) Find out which forwarders are...
        
         
           by 
           
                
                    
                        Robbie1194
                    
                
           
             
             
               Communicator
             
           
           in
           Deployment Architecture
           
           
              
               07-10-2017
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Does Splunk support two search head clusters with one indexer cluster? Basically we have 3 search heads clustered. we...
        
         
           by 
           
                
                    
                        ankithreddy777
                    
                
           
             
             
               Contributor
             
           
           in
           Deployment Architecture
           
           
              
               01-10-2017
             
           
         
        | 
		
		1
   | 
	  
	  3
	 | |||
| 
        Currently we have 1 multisite indexing cluster, 1 multisite search head cluster, a deployer and a master node. Planni...
        
         
           by 
           
                
                    
                        sajeshpp
                    
                
           
             
             
               Path Finder
             
           
           in
           Deployment Architecture
           
           
              
               07-07-2017
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hi, 
  I want to calculate dispatch directory size in Splunk to help in Splunk performance monitoring. Can anyone ple...
        
         
           by 
           
                
                    
                        MousumiChowdhur
                    
                
           
             
             
               Contributor
             
           
           in
           Deployment Architecture
           
           
              
               07-06-2017
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Would it be possible to bring the new servers online into the respective pools and have them sync in such a way that ...
        
         
           by 
           
                
                    
                        trinity1571
                    
                
           
             
             
               New Member
             
           
           in
           Deployment Architecture
           
           
              
               07-05-2017
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        I am trying to forward events from my current SIEM to the Universal forwarder using UDP and port 9514. When I run a t...
        
         
           by 
           
                
                    
                        pfabrizi
                    
                
           
             
             
               Path Finder
             
           
           in
           Deployment Architecture
           
           
              
               07-05-2017
             
           
         
        | 
		
		0
   | 
	  
	  7
	 | |||
| 
        We have a deployment with approximately 500 linux systems that are sending logs via syslog on a single indexer. In so...
        
         
           by 
           
                
                    
                        lightech1
                    
                
           
             
             
               Path Finder
             
           
           in
           Deployment Architecture
           
           
              
               06-28-2017
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        I've recently upgraded to Splunk 6.6.0 and now seem to be having a problem with one of my indexes; every time I searc...
        
         
           by 
           
                
                    
                        jmangs
                    
                
           
             
             
               Explorer
             
           
           in
           Deployment Architecture
           
           
              
               05-05-2017
             
           
         
        | 
		
		2
   | 
	  
	  4
	 | |||
| 
        I have a few sh scripts scheduled to run every few min and those stop recently, and print this error in the log. To w...
        
         
           by 
           
                
                    
                        harry521
                    
                
           
             
             
               New Member
             
           
           in
           Deployment Architecture
           
           
              
               06-26-2017
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hi, 
  Is there any configuration in Splunk forwarder to delete old splunkd logs, metric logs etc.
        
         
           by 
           
                
                    
                        RAYUDU_NARA
                    
                
           
             
             
               Explorer
             
           
           in
           Deployment Architecture
           
           
              
               06-30-2017
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I basically have roles which install the forwarder with whom I might wish to do some local testing.  When testing loc...
        
         
           by 
           
                
                    
                        davidheward
                    
                
           
             
             
               New Member
             
           
           in
           Deployment Architecture
           
           
              
               06-29-2017
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        New 6.0.x/6.1.x installation and both Indexer and Search Head seem to have latency and not performing as expected! 
 ...
        
         
           by 
           
                
                    
                        abonuccelli_spl
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Deployment Architecture
           
           
              
               07-01-2014
             
           
         
        | 
		
		2
   | 
	  
	  9
	 | |||
| 
        I have situtationn where i have cluster master which managed the indexer cluster . I am getiing data in load balancin...
        
         
           by 
           
                
                    
                        aab5272
                    
                
           
             
             
               Engager
             
           
           in
           Deployment Architecture
           
           
              
               06-28-2017
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Any help will be appreciated, i trying from long back how to check missing forwarders.
        
         
           by 
           
                
                    
                        Rocky31
                    
                
           
             
             
               Path Finder
             
           
           in
           Deployment Architecture
           
           
              
               06-28-2017
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        We want to ingest data from databases to our indexer .Would it be recommended to use heavy forwarder or UF ? Also can...
        
         
           by 
           
                
                    
                        aab5272
                    
                
           
             
             
               Engager
             
           
           in
           Deployment Architecture
           
           
              
               06-27-2017
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        My first few attempts at rebalancing were pretty great. No muss, no fuss. They ran for about 12 hours and like magic ...
        
         
           by 
           
                
                    
                        twinspop
                    
                
           
             
             
               Influencer
             
           
           in
           Deployment Architecture
           
           
              
               04-04-2017
             
           
         
        | 
		
		0
   | 
	  
	  8
	 | |||
| 
        So we are trying to design a solution and we want two layers for forwarding . At the first layer universal forwarder ...
        
         
           by 
           
                
                    
                        aab5272
                    
                
           
             
             
               Engager
             
           
           in
           Deployment Architecture
           
           
              
               06-26-2017
             
           
         
        | 
		
		0
   | 
	  
	  4
	 |