Discussions
Thread Info | |||||
---|---|---|---|---|---|
I have a log file that gets rotated (foo.log becomes foo.log.1, foo.log.1 becomes foo.log.2, etc). Every time the fil...
by
kkalmbach
Path Finder
in
Deployment Architecture
08-24-2011
|
0
|
1
| |||
We have many legacy scripts that send status messages by email. We strongly prefer not to modify the scripts and inst...
by
dominiquevocat
SplunkTrust
in
Deployment Architecture
08-04-2011
|
1
|
2
| |||
Does anyone know what the read/write block size is (ex. 4KB, 8KB, 16KB, etc) that the Splunk application uses to writ...
by
maverick
Splunk Employee
in
Deployment Architecture
08-23-2011
|
1
|
2
| |||
I have added a few Ubuntu Linux server. They are forwarding log data no problem, and I can search it. Problem is that...
by
hyoung
New Member
in
Deployment Architecture
04-04-2011
|
0
|
2
| |||
Is there a maximum number of forwarders that a single indexer can support?
by
lihongyan_84
Explorer
in
Deployment Architecture
08-16-2011
|
1
|
1
| |||
After ran a diag for UniversalForwarder/LightWeightForwarder, found that var/lib/splunk/fishbucket/db is empty. Anyth...
by
zliu
Splunk Employee
in
Deployment Architecture
08-03-2011
|
1
|
1
| |||
Is it possible to blacklist ip ranges in serverclass.conf? Something like this?
[serverClass:test-type] machineTyp...
by
trross33
Path Finder
in
Deployment Architecture
08-01-2011
|
0
|
1
| |||
Now that Splunk 4.2 introduced the concept of volumes for storing indexes, I'd like to change my configs to use it. (...
by
supersleepwalke
Communicator
in
Deployment Architecture
07-27-2011
|
2
|
1
| |||
I simulate client, forwarder and indexer on the same machine (different ports and so) -> REHL 5.6
Somehow now, my ...
by
LCM
Contributor
in
Deployment Architecture
07-26-2011
|
1
|
4
| |||
Greeting, My Splunk installation is simply configured to collect syslog messages (udp 514) and nothing fancy... and I...
by
hellou
New Member
in
Deployment Architecture
07-26-2011
|
0
|
3
| |||
I'm trying to use an approach like Search Head Pooling to share auth info to set up search head pooling. I'm thinking...
by
Steve_Litras
Path Finder
in
Deployment Architecture
07-20-2011
|
1
|
1
| |||
Is it correct to assume that if you restart the server while indexing log files, the server will resume where it stop...
by
chca
Path Finder
in
Deployment Architecture
07-20-2011
|
1
|
1
| |||
I am having trouble getting the deploymentclient.conf setting phoneHomeIntervalInSecs to be followed.
Using a uni...
by
gfriedmann
Communicator
in
Deployment Architecture
06-22-2011
|
0
|
7
| |||
In my deploymentclient.conf I have added the phoneHomeIntervalInSecs to be 1800 seconds (30 minutes) to override the ...
by
Ellen
Splunk Employee
in
Deployment Architecture
07-18-2011
|
5
|
1
| |||
When collecting remote event logs how frequently does Splunk poll the remote host and is this configurable?
by
Jodge
Path Finder
in
Deployment Architecture
07-12-2011
|
0
|
2
| |||
Hi yesterday I was running Splunk fine and then I went to restart Splunk because I installed the SEP app and it was t...
by
hawk0000
New Member
in
Deployment Architecture
07-07-2011
|
0
|
2
| |||
I would like to understand if there is a way to monitor if a unix log file has been tampered with (lines deleted or m...
by
brianokelly
Explorer
in
Deployment Architecture
06-29-2011
|
1
|
4
| |||
One of my managed apps via Deployment Server is the Search app. Now, due to requirement changes, each Deployment clie...
by
Ellen
Splunk Employee
in
Deployment Architecture
06-30-2011
|
2
|
2
| |||
I am already newbie to splunk and ip-port config at linux env.
I have two instances at Amazon, i set up splunkforw...
by
ksaritek
Engager
in
Deployment Architecture
06-30-2011
|
0
|
1
| |||
We currently have a forwarder with multiple NICs.
eth0: 192.168.1.x
eth1: 192.168.2.x
All of the data comes i...
by
Greg_LeBlanc
Path Finder
in
Deployment Architecture
06-29-2011
|
0
|
3
| |||
I think search head pool is required for multiple search heads sharing configurations.
What's the benefit of makin...
by
hochit
Path Finder
in
Deployment Architecture
06-27-2011
|
1
|
3
| |||
I am running into the "approaching max search limit per cpu" warning message on my search head.
I have 1 search he...
by
gfriedmann
Communicator
in
Deployment Architecture
06-03-2011
|
2
|
1
| |||
My app server gets restarted once a day. Sometimes, Splunk will treat individual lines as unique log entry. So what s...
by
scott74nyc
New Member
in
Deployment Architecture
06-24-2011
|
0
|
1
| |||
An enterprise network has many sub-networks each with UniversalForwarders forwarding to a central pool of Indexers. T...
by
sdwilkerson
Contributor
in
Deployment Architecture
06-22-2011
|
0
|
2
| |||
maxTotalDataSizeMB parameter controls the index size as a whole so this includes hotdb, warmdb and colddb, but how ab...
by
elusive
Splunk Employee
in
Deployment Architecture
06-20-2011
|
2
|
1
|