Deployment Architecture

Deployment Architecture
Community Activity
imacdonald2
My plan was create a search head with a basic app for each department. Users are allowed to save search results in in...
by imacdonald2 Path Finder in Deployment Architecture 01-05-2012
1 1
1
1
imrago
Hi, I have a simple setup, one searchhead and one indexer. Starting from the latest upgrade to 4.2.4 the size of bun...
by imrago Contributor in Deployment Architecture 12-27-2011
0 2
0
2
Splunker
Folks, I have a Splunk 4.2.4 search-head and indexer on another machine in a distributed setup. I'm getting an erro...
by Splunker Communicator in Deployment Architecture 12-26-2011
0 1
0
1
melonman
Hi there, When I issued "splunk restart" command, it takes more than 5 min. Looks like stopping splunk takes most of...
by melonman Motivator in Deployment Architecture 12-21-2011
2 3
2
3
mark
Hi All, Our company has recently hopped on the Splunk bandwagon and we've set up a small distributed environment of ...
by mark Path Finder in Deployment Architecture 12-20-2011
0 2
0
2
brentsinawski
Hello, We are using splunk for our alerting, log collection and performance information on about 80 servers so far. W...
by brentsinawski Explorer in Deployment Architecture 12-19-2011
0 1
0
1
uptimebox
Debian GNU/Linux 6.0 (Squeeze) # splunk --version Splunk Universal Forwarder 4.2 (build 96430) # splunk enable boot-...
by uptimebox Engager in Deployment Architecture 12-18-2011
3 1
3
1
anirbanukil
I went through the documentation at "http://docs.splunk.com/Documentation/Splunk/4.2.2/Admin/SendSNMPtrapstoothersyst...
by anirbanukil Explorer in Deployment Architecture 12-15-2011
0 2
0
2
appmandan
I have been researching how to backup splunk, and a lot of the information I'm finding pertains to the indexes. Is t...
by appmandan Path Finder in Deployment Architecture 12-14-2011
0 2
0
2
DTERM
Is there any application, process, or feature of splunk that will preduct future behavior based on past performance? ...
by DTERM Contributor in Deployment Architecture 12-10-2011
0 1
0
1
bnklein
I am new to Splunk and just installed splunk-4.2.4-110225-linux-2.6-x86_64.rpm on Red Hat Linux Enterprise 6. The in...
by bnklein Engager in Deployment Architecture 12-09-2011
4 2
4
2
r999
Can the license master config point to a DNS name? I.e if there was an issue with Licese master server we do not wa...
by r999 Path Finder in Deployment Architecture 12-09-2011
1 2
1
2
Starlette
Hai there, I have a indexer with index=a index=b, and a searchead connected to it ( default no changes yet) When ru...
by Starlette Contributor in Deployment Architecture 12-07-2011
0 2
0
2
yzidell
how can configure splunk Home -> All forwarders to the FQDN instead of just the host name? Thanks
by yzidell Engager in Deployment Architecture 12-07-2011
1 2
1
2
clyde772
Hello fellow splunkers! Anybody out there have experience with Splunk on HP-UX where it just consumes too much CPU r...
by clyde772 Communicator in Deployment Architecture 12-02-2011
1 5
1
5
rkanalyst
I want to group the cluster value based on the similar punct. I have used the following query. tag="tagname" sourcety...
by rkanalyst Explorer in Deployment Architecture 12-01-2011
0 1
0
1
cwi
concatenating fields at index time doesn't seem to work. I have the following transform: [gztdnv] REGEX = <td>\s+(\S...
by cwi Engager in Deployment Architecture 12-01-2011
0 6
0
6
mfrost8
Our search heads are on our indexers (i.e. they're the same thing). We're looking at doing search head pooling in th...
by mfrost8 Builder in Deployment Architecture 11-29-2011
0 2
0
2
Mick
My hardware vendor just called and offered me a great deal on a Sun SPARC Enterprise T5120 Server, he said it would b...
by Mick Splunk Employee Splunk Employee in Deployment Architecture 11-28-2011
10 3
10
3
Damien_Dallimor
Is there any documentation around on how scheduler state works when deploying multiple search heads in a search head ...
by Damien_Dallimor Ultra Champion in Deployment Architecture 11-28-2011
0 3
0
3
Dark_Ichigo
Im always getting this error related to the internal _audit index in Splunk: **received event for unconfigured/disab...
by Dark_Ichigo Builder in Deployment Architecture 11-27-2011
0 3
0
3
jchensor
Hello, everyone. When it comes to Indexers, there is an option you can use in "inputs.conf" where you add the follow...
by jchensor Communicator in Deployment Architecture 11-21-2011
0 1
0
1
rossikwan
Hi all, My UNIX (Solaris) host installed Splunk universal forwarder in which some kind of monitor in inputs.conf is ...
by rossikwan Path Finder in Deployment Architecture 11-20-2011
0 7
0
7
gts1999
Hi, is anyone doing this sort of configuration? AIX HACMP cluster with shared storage, log file is on shared storage....
by gts1999 Engager in Deployment Architecture 11-16-2011
1 2
1
2
richard_whiffen
I have a strange one. I'm migrating hosts to a different indexer to redistribute my workload. Last week from the co...
by richard_whiffen Explorer in Deployment Architecture 11-15-2011
0 4
0
4
Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...
Top Solution Authors