Deployment Architecture

Deployment Architecture
Community Activity
msarro
Hi everyone. I have just deployed well over 300 forwarders over the past 48 hours. Our serverclass.conf file is broke...
by msarro Builder in Deployment Architecture 11-06-2013
1 1
1
1
nikhilagrawal
we have two separate App running on one server and need to monitor both Application (different log path). [target-b...
by nikhilagrawal Path Finder in Deployment Architecture 11-06-2013
0 3
0
3
sohovfx
Hey there, What is the best way (if any) to configure the Receiver host to accept forwarded data from itself? I th...
by sohovfx New Member in Deployment Architecture 11-05-2013
0 3
0
3
shervinfernando
I upgraded my clustered index and after the upgrade /opt/splunk/bin/splunk show cluster-bundle-status shows all peer...
by shervinfernando Explorer in Deployment Architecture 11-05-2013
1 5
1
5
cimi
How to export slunk data o sql server?
by cimi New Member in Deployment Architecture 11-04-2013
0 1
0
1
spyme72
i created a new index by creating a new TA app. i added the indexes.conf to the default folder . when i pushed the co...
by spyme72 Path Finder in Deployment Architecture 11-01-2013
0 1
0
1
felipesewaybric
hey guys, i need some help i have 3 machines, and 2 of than is receiving data, and i want to user the third machine ...
by felipesewaybric Contributor in Deployment Architecture 11-01-2013
0 1
0
1
the_wolverine
I'd like to set up a new 5.0.3 cluster but I'd like to ALSO point the SH to my old 4.3 indexers so that I do not have...
by the_wolverine Champion in Deployment Architecture 11-01-2013
0 1
0
1
BenAveling
What is the best practice for distributed data across 2 or more data-centers? The objective is geographic redundancy...
by BenAveling Path Finder in Deployment Architecture 11-01-2013
1 1
1
1
somesoni2
I am creating a java program using SPlunk SDK which takes a string data from a application source and pass it to a sp...
by Revered Legend in Deployment Architecture 10-31-2013
0 2
0
2
bobwalden
Suppose I want to delete a bucket from an indexer for some reason. Can I: stop splunkdelete the offending bucketstar...
by bobwalden Explorer in Deployment Architecture 10-31-2013
1 1
1
1
sunrise
Hi splunkers, Yesterday, I was monitoring the splunk_access.log and found the log messages that deployment clients ...
by sunrise Contributor in Deployment Architecture 10-30-2013
0 3
0
3
jodros
Does anyone know how to accomplish this? I have tried utilizing the "Restrict search terms" but it is not working. ...
by jodros Builder in Deployment Architecture 10-30-2013
0 4
0
4
nbeyer_cerner
I'm attempting to replace the /opt/splunk/var folder with the /var folder via symlink to keep relatively small amount...
by nbeyer_cerner New Member in Deployment Architecture 10-30-2013
0 1
0
1
agodoy
Hello, I have timestamps in the following format. 1383058343.661030 I added the following to my props.conf. TIME_...
by agodoy Communicator in Deployment Architecture 10-29-2013
0 3
0
3
jpass
I have Splunk 4.32 installed on Linux. Today I stopped Splunk, used the 'clean eventdata index_name' to clear up some...
by jpass Contributor in Deployment Architecture 10-28-2013
0 3
0
3
tmarlette
I am attempting to find out the average latency of my requests by ip, per hour, over a 24 hour period. I'm sure i'm m...
by tmarlette Motivator in Deployment Architecture 10-25-2013
0 1
0
1
peter_gianusso
On the indexer in Splunk 6 getting this error message 10-25-2013 17:00:11.024 -0400 WARN IndexConfig - Max bucket s...
by peter_gianusso Communicator in Deployment Architecture 10-25-2013
2 2
2
2
a212830
Hi, I have a customer who wants to utilize their own search-head to read some Splunk data that I administer. In the...
by a212830 Champion in Deployment Architecture 10-25-2013
1 2
1
2
jchensor
Hello, all! As a "TL;DR" to get right to the point, my main question is this: What is the minimum needed to be inst...
by jchensor Communicator in Deployment Architecture 10-25-2013
1 2
1
2
msarro
When you define a whitelist or blacklist, suppose you have a set of servers which are differentiated by a character a...
by msarro Builder in Deployment Architecture 10-23-2013
0 3
0
3
bigtyma
I noticed we can enabled the 'current_only' feature for Windows event logs, Does the UF for *NIX support the same typ...
by bigtyma Communicator in Deployment Architecture 10-21-2013
0 3
0
3
semenko
I had a problem where my output.conf file was incorrect (Linux formatting, instead ^M newline formatted for Windows)....
by semenko New Member in Deployment Architecture 10-21-2013
0 1
0
1
semenko
I'm new to Splunk, and trying it out in a small environment of Windows 8 machines. I have a Splunk frontend (collect...
by semenko New Member in Deployment Architecture 10-21-2013
0 4
0
4
gdavid
Is it possible to install splunk db connect on a universal forwarder? I would like to fetch the data and just forwa...
by gdavid Path Finder in Deployment Architecture 10-18-2013
0 1
0
1
Get Updates on the Splunk Community!

From Raw Data to Executive-Ready Stories, Faster

Build Data Stories for Every Audience  A dashboard is rarely just a dashboard. It might be the view an ...

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...