Deployment Architecture

Deployment Architecture
Community Activity
jcgever
Got a customer wanting the UFs to send data to the forcepoint DLP and then to the intermediate heavy forwarder. The r...
by jcgever Explorer in Deployment Architecture 11-21-2023
0 1
0
1
AL3Z
Hi,I had blacklisted the "(?:ParentProcessName).+(?:C:\\Program Files\\Windows Defender Advanced Threat Protection\\)...
by AL3Z Builder in Deployment Architecture 11-21-2023
0 17
0
17
pvarelab
I have a Splunk Cloud instance where we send logs from servers with the Universal Forwarder installed. All UF are man...
by pvarelab Path Finder in Deployment Architecture 11-21-2023
0 3
0
3
sigma
Hi allI created an environment with following instances:cluster masterthree search headsfour indexersheavy forwarderl...
by sigma Path Finder in Deployment Architecture 11-19-2023
0 2
0
2
blkscorpio
How Do I get the instance for heavy forwader for my vm box for set up. Is the UF instance differ from HF instance? 
by blkscorpio Observer in Deployment Architecture 11-18-2023
0 6
0
6
smithy001
if we configure a fast volume for hot/warm and slower spindles for cold and set maxVolumeDataSizeMB to enforce sizes....
by smithy001 Explorer in Deployment Architecture 11-15-2023
0 5
0
5
edoardo_vicendo
Hello,Supposing you have a Search Head in Cloud, doing Federated Searches to other Search Heads on-prem, which is the...
by edoardo_vicendo Builder in Deployment Architecture 11-14-2023
0 3
0
3
clayraed
I have created an app for a team that I work with, and have set up mapping from our SAML auth so that the people on t...
by clayraed Loves-to-Learn in Deployment Architecture 11-10-2023
0 0
0
0
spl10
Hi TeamGetting this error message frequently in internal logs of Splunk.Error in 'where' command: The expression is m...
by spl10 Explorer in Deployment Architecture 11-09-2023
0 1
0
1
maede_yavari
Hi,we have deployed a search head cluster with two search head and one deployer.when we run : /opt/splunk/bin/splunk ...
by maede_yavari Explorer in Deployment Architecture 11-08-2023
0 2
0
2
Bisho-Fouad
a problem where the cluster master and deployment server in the distributed Splunk environment cannot be logged in vi...
by Bisho-Fouad Explorer in Deployment Architecture 11-06-2023
0 14
0
14
red2play
Index Size is 5.3G vs 1.6G Raw Data:Raw data Index on Splunk This is also affecting our licensing plans as well.  Thi...
by red2play Loves-to-Learn in Deployment Architecture 11-03-2023
0 1
0
1
FPERVIL
One the search head that our SOC uses, i get the following:IOWaitSum of 3 highest per-cpu iowaits reached red thresho...
by FPERVIL Explorer in Deployment Architecture 11-01-2023
0 1
0
1
Venkataraman
Dear Team, We have a cluster step up where 3 search head(cluster) , 3 indexer(cluster),1 index master,1 deployer, 1 ...
by Venkataraman Engager in Deployment Architecture 10-31-2023
0 5
0
5
shriramwasule
Hi All,Our scenario is like, in our AWS environment ,we want to collect our logs by using universal forwarder from ou...
by shriramwasule New Member in Deployment Architecture 10-31-2023
0 2
0
2
maede_yavari
Hello,we have a data center with several type of equipment such as servers, switches, routers, EDR, some IOT Sensors,...
by maede_yavari Explorer in Deployment Architecture 10-30-2023
0 7
0
7
vijreddy30
Hi team, My project Zone  1  have Deployment server , HF and (SH+Indexer)Zone 2  also  Deployment server ,HF and (SH+...
by vijreddy30 Loves-to-Learn Everything in Deployment Architecture 10-27-2023
0 1
0
1
dhana22
Hello All, We are setting up a Splunk enterprise multisite cluster, and i was wondering can we have 2 license master,...
by dhana22 Explorer in Deployment Architecture 10-26-2023
0 1
0
1
VK18
Hi All,We have approximately 100 Splunk Universal Forwarders (UFs) installed at a remote site, and we're interested i...
by VK18 Explorer in Deployment Architecture 10-26-2023
0 4
0
4
AL3Z
Hello,Upon attempting to execute the command $SPLUNK_HOME/bin/splunk reload deploy-server following the update of app...
by AL3Z Builder in Deployment Architecture 10-24-2023
0 1
0
1
vijreddy30
Hi All, Currently Development zone-1 HF and( SearchHead+Indexer ) single instanceQA -HF,Deploymentserver and Deployme...
by vijreddy30 Loves-to-Learn Everything in Deployment Architecture 10-23-2023
0 4
0
4
gcusello
Hi at all,I have to configure a multisite Indexer Cluster and I have a dubt:in the Splunk architectig course, the ind...
by SplunkTrust SplunkTrust in Deployment Architecture 10-20-2023
0 3
0
3
Darthsplunker
Hello, all!Im hopefully looking for an ELI5 (explain like im 5) on the best way to migrate indexer cluster database t...
by Darthsplunker Path Finder in Deployment Architecture 10-19-2023
1 3
1
3
sandeepreddy947
I have a bucket in fixup tasks in indexer cluster-> bucket status, its been struck.  Both SF & RF. So, both SF and RF...
by sandeepreddy947 Path Finder in Deployment Architecture 10-18-2023
0 2
0
2
woodlandrelic
Been having trouble with my indexers but everything is fine now and up. But now my RF and SF are still not been met. ...
by woodlandrelic Path Finder in Deployment Architecture 10-18-2023
0 7
0
7
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...
Top Solution Authors