Deployment Architecture

Deployment Architecture
Community Activity
mudragada
Hi, We have a cluster setup - where we have 1. Heavy Forwarders 2. Indexer servers and an indexer master 3. Search h...
by mudragada Path Finder in Deployment Architecture 02-01-2017
0 2
0
2
manderson7
I run the following search on the search head and receive results that I expect: index=c_metrics Severity!="Very Low...
by manderson7 Contributor in Deployment Architecture 02-01-2017
0 6
0
6
archspangler
What conf file controls the below message? I noticed the following warning message after upgrading my deployment ser...
by archspangler Path Finder in Deployment Architecture 02-01-2017
1 14
1
14
shandman
Having a heck of a time implementing an application. (In this case the app=dnslookup). Here is my command and error ...
by shandman Path Finder in Deployment Architecture 01-31-2017
1 6
1
6
Jrubalcaba
Does anyone know if this holds valid in RHEL 7.2: Recently I saw an article regarding Splunk performance and Transpa...
by Jrubalcaba Explorer in Deployment Architecture 01-31-2017
0 8
0
8
mdsnmss
I am trying to change the default time range when opening the search app. I have found several answers in other quest...
by SplunkTrust SplunkTrust in Deployment Architecture 01-31-2017
0 2
0
2
kbecker
Does anybody happen to know what the following error means and how to resolve it? I linked this back to a saved sear...
by kbecker Communicator in Deployment Architecture 01-31-2017
5 7
5
7
salem34
Hi Ninjas I have two different json logs which looks like this: {"version":"1.1","host":"t800.skynet.com","short_me...
by salem34 Path Finder in Deployment Architecture 01-30-2017
0 14
0
14
bbazian
I am trying to get additional logs sent to Splunk Cloud from a Windows domain controller. I modified my inputs.conf ...
by bbazian New Member in Deployment Architecture 01-30-2017
0 8
0
8
biec1
Our Splunk server is in UTC time zone,but the Events time zone is in CET. Current Splunk Server Time:- Fri Jan 27 12...
by biec1 Explorer in Deployment Architecture 01-28-2017
0 4
0
4
kdoonan
I'm trying to keep the server.conf in a consistent state over a few clustered indexes, but I'm having a bit of troubl...
by kdoonan Explorer in Deployment Architecture 01-27-2017
1 6
1
6
nikkuu
I am trying to list out common uid on two different hosts. I am using this but this give a visual of all uids includi...
by nikkuu New Member in Deployment Architecture 01-27-2017
0 2
0
2
MikeFarmITP
I'm not sure what I'm doing wrong here, but trying to configure a universal forwarder on Windows so it automatically ...
by MikeFarmITP New Member in Deployment Architecture 01-27-2017
0 2
0
2
aoliullah
Hi. I am just confused a bit with raw and indexed/indexing data being stored by the index. So does the index store bo...
by aoliullah Path Finder in Deployment Architecture 01-27-2017
0 2
0
2
netprince
Hi folks, I have been searching for ways to back up my Splunk 6.4.1 which is on CentOS and got these results: http:/...
by netprince New Member in Deployment Architecture 01-26-2017
0 5
0
5
princemanto2580
Hello, After several trial and error, I can not sort out the issue for additional Indexes creation for cluster peers...
by princemanto2580 Path Finder in Deployment Architecture 01-26-2017
0 4
0
4
aoliullah
Hi. Could someone explain to me the difference between Distributed and Clustered environment in relation to Splunk? I...
by aoliullah Path Finder in Deployment Architecture 01-26-2017
0 3
0
3
Koushik_Katta
Indexer is filled up , i have got the retention policy accoridngly
by Koushik_Katta Explorer in Deployment Architecture 01-25-2017
0 3
0
3
princemanto2580
Hello Splunker, I prepared one lab with below instance to see real-time Single Site Index Clustering. But after conf...
by princemanto2580 Path Finder in Deployment Architecture 01-24-2017
0 15
0
15
MousumiChowdhur
I have six indexers in cluster and 2 search heads. Only one of my indexers is showing >90% CPU load in some other ser...
by MousumiChowdhur Contributor in Deployment Architecture 01-24-2017
0 4
0
4
ankithreddy777
We want to build a search head cluster. May I know which storage is preferable: SAN or local drive? And why?
by ankithreddy777 Contributor in Deployment Architecture 01-23-2017
0 3
0
3
saurabh009
Hi, I am unable to remove search peers from the Distributed Management Console. When I try to remove it from Splunk W...
by saurabh009 Path Finder in Deployment Architecture 01-23-2017
1 2
1
2
sat94541
I have Cluster Master with Two indexes. The Clustering Master Node screen is showing only index _audit and _interna...
by sat94541 Communicator in Deployment Architecture 01-23-2017
0 2
0
2
srajarat2
I had just setup Splunk with indexer clustering (RF-3, SF-2) with no data and initially loaded 1TB of syslog file usi...
by srajarat2 Path Finder in Deployment Architecture 01-22-2017
0 3
0
3
jwalthour
After setting repFactor = 2 at the default level and running with that for awhile, can I now go in on a per indexer b...
by jwalthour Communicator in Deployment Architecture 01-22-2017
0 3
0
3
Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...