Deployment Architecture

Deployment Architecture
Community Activity
HenryTaylor
how do you create a scalable splunk deployment of forwarders to specific index servers that report to a search head?
by HenryTaylor Explorer in Deployment Architecture 03-09-2013
0 2
0
2
las
Hi. I have been unable to find the time the deployment server uses to evict clients that it haven't heard from. I w...
by las Contributor in Deployment Architecture 03-09-2013
0 4
0
4
sriva6
Hi, I have all my inputs pointing at index "main" on my existing splunk server. I have added a new indexer to my spl...
by sriva6 New Member in Deployment Architecture 03-07-2013
0 2
0
2
danlynch
I would like to create a search that would identify hosts that have triggered a snort alert, e.g. stream5: TCP sess...
by danlynch New Member in Deployment Architecture 03-06-2013
0 4
0
4
dabel
I have forwarders setup on a bunch of different servers sending to a single manager, how can I separate the inputs in...
by dabel Engager in Deployment Architecture 03-06-2013
0 1
0
1
catch_mili
How to major uptime of the server using splunk
by catch_mili Explorer in Deployment Architecture 03-06-2013
0 1
0
1
hugocvg
My splunk instance grew and now my deployment server is not enough. I have 2 search heads, 4 indexers and 261 forward...
by hugocvg Explorer in Deployment Architecture 03-04-2013
0 4
0
4
mship
Running Splunk 5.0.1 on windows 2008R2. I had to move my index to another server...followed the steps perfectly...rol...
by mship Path Finder in Deployment Architecture 03-04-2013
0 3
0
3
mship
I am running Splunk 5.0.1, am in a Windows workgroup enviornment, and have 2 Windows 2008R2 servers as indexers for r...
by mship Path Finder in Deployment Architecture 03-04-2013
0 5
0
5
danlynch
Hello, I've added a unix script to that identifies all NATed traffic across my BSD firewall (pf): /usr/local/sbin/...
by danlynch New Member in Deployment Architecture 03-02-2013
0 3
0
3
Daniel_Edwards
Hello, I'm getting input from a log file the contents of which are a long listing a directory containing .rpm files....
by Daniel_Edwards Explorer in Deployment Architecture 03-01-2013
0 7
0
7
1234testtest
Hi, Does the 500MB limit apply to the open source version of Splunk (Java sdk that Splunk opens up)
by 1234testtest Path Finder in Deployment Architecture 03-01-2013
0 2
0
2
rmorlen
We are running a standalone deployment server version 4.3.5. Using the search "index=_* hostname=SplunkInfrastructur...
by rmorlen Splunk Employee Splunk Employee in Deployment Architecture 02-28-2013
1 2
1
2
jfaldmo
There are two issues I am having with a new setup. We have 2 search heads and 3 indexers. The first issue is with a s...
by jfaldmo Explorer in Deployment Architecture 02-27-2013
0 2
0
2
nickhills
I am preparing for a new fresh deployment which is expected to take a lot of data (and users) going forwards. For thi...
by nickhills Ultra Champion in Deployment Architecture 02-27-2013
0 3
0
3
oestreicher
Hi, I am looking into the the new index replication feature. I read the documentation and what I understand is that ...
by oestreicher Explorer in Deployment Architecture 02-26-2013
2 4
2
4
alenseb
Hi Guys, I am trying backup & restore splunk into a more powerful server. I followed the document where in it says ...
by alenseb Communicator in Deployment Architecture 02-25-2013
0 1
0
1
miteshvohra
After installing Splunk 5.0.2 release on Ubuntu Server 12.10 (with kernel 3.5.0-17), I am frequently getting the foll...
by miteshvohra Contributor in Deployment Architecture 02-25-2013
0 4
0
4
hugocvg
is there a problem if my deployment server and one of my indexers are running in the same server? because both of the...
by hugocvg Explorer in Deployment Architecture 02-25-2013
0 1
0
1
cvitale
I just completed building a clustered splunk environment. it currently includes a search, 2 indexers, a master node ...
by cvitale New Member in Deployment Architecture 02-24-2013
0 3
0
3
iKate
Hello, Can someone explain why there is no inbuilt functionality of deleting just some indexed data - from particula...
by iKate Builder in Deployment Architecture 02-24-2013
0 1
0
1
jtacy
Howdy, We're developing a multi-tenant Splunk design using multiple server IPs rather than ports. This has worked gr...
by jtacy Builder in Deployment Architecture 02-21-2013
1 1
1
1
perlish
how can I backup config and data,then restore them ? config:user,permition,search,view,app and so on. data:history lo...
by perlish Communicator in Deployment Architecture 02-21-2013
0 2
0
2
dcparker
Hey, I have set up a clustered Splunk deployment in a lab environment to test. By default, I see _internal and _audi...
by dcparker Path Finder in Deployment Architecture 02-21-2013
1 2
1
2
tiberious726
I am aware that the deployment server compares the hash of its copy of a given app against the hash the apps of its d...
by tiberious726 Path Finder in Deployment Architecture 02-20-2013
0 4
0
4
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...
Top Solution Authors