Deployment Architecture

Deployment Architecture
Community Activity
supersleepwalke
Now that Splunk 4.2 introduced the concept of volumes for storing indexes, I'd like to change my configs to use it. (...
by supersleepwalke Communicator in Deployment Architecture 07-27-2011
2 1
2
1
LCM
I simulate client, forwarder and indexer on the same machine (different ports and so) -> REHL 5.6 Somehow now, my Sp...
by LCM Contributor in Deployment Architecture 07-27-2011
1 4
1
4
hellou
Greeting, My Splunk installation is simply configured to collect syslog messages (udp 514) and nothing fancy... and I...
by hellou New Member in Deployment Architecture 07-26-2011
0 3
0
3
Steve_Litras
I'm trying to use an approach like Search Head Pooling to share auth info to set up search head pooling. I'm thinking...
by Steve_Litras Path Finder in Deployment Architecture 07-20-2011
1 1
1
1
chca
Is it correct to assume that if you restart the server while indexing log files, the server will resume where it stop...
by chca Path Finder in Deployment Architecture 07-20-2011
1 1
1
1
gfriedmann
I am having trouble getting the deploymentclient.conf setting phoneHomeIntervalInSecs to be followed. Using a unive...
by gfriedmann Communicator in Deployment Architecture 07-18-2011
0 7
0
7
Ellen
In my deploymentclient.conf I have added the phoneHomeIntervalInSecs to be 1800 seconds (30 minutes) to override the ...
by Ellen Splunk Employee Splunk Employee in Deployment Architecture 07-18-2011
5 1
5
1
Jodge
When collecting remote event logs how frequently does Splunk poll the remote host and is this configurable?
by Jodge Path Finder in Deployment Architecture 07-12-2011
0 2
0
2
hawk0000
Hi yesterday I was running Splunk fine and then I went to restart Splunk because I installed the SEP app and it was t...
by hawk0000 New Member in Deployment Architecture 07-07-2011
0 2
0
2
brianokelly
I would like to understand if there is a way to monitor if a unix log file has been tampered with (lines deleted or m...
by brianokelly Explorer in Deployment Architecture 07-05-2011
1 4
1
4
Ellen
One of my managed apps via Deployment Server is the Search app. Now, due to requirement changes, each Deployment clie...
by Ellen Splunk Employee Splunk Employee in Deployment Architecture 07-05-2011
2 2
2
2
ksaritek
I am already newbie to splunk and ip-port config at linux env. I have two instances at Amazon, i set up splunkforwar...
by ksaritek Engager in Deployment Architecture 06-30-2011
0 1
0
1
Greg_LeBlanc
We currently have a forwarder with multiple NICs. eth0: 192.168.1.x eth1: 192.168.2.x All of the data comes in et...
by Greg_LeBlanc Path Finder in Deployment Architecture 06-29-2011
0 3
0
3
hochit
I think search head pool is required for multiple search heads sharing configurations. What's the benefit of making ...
by hochit Path Finder in Deployment Architecture 06-28-2011
1 3
1
3
gfriedmann
I am running into the "approaching max search limit per cpu" warning message on my search head. I have 1 search head...
by gfriedmann Communicator in Deployment Architecture 06-24-2011
2 1
2
1
scott74nyc
My app server gets restarted once a day. Sometimes, Splunk will treat individual lines as unique log entry. So what s...
by scott74nyc New Member in Deployment Architecture 06-24-2011
0 1
0
1
sdwilkerson
An enterprise network has many sub-networks each with UniversalForwarders forwarding to a central pool of Indexers. T...
by sdwilkerson Contributor in Deployment Architecture 06-23-2011
0 2
0
2
elusive
maxTotalDataSizeMB parameter controls the index size as a whole so this includes hotdb, warmdb and colddb, but how ab...
by elusive Splunk Employee Splunk Employee in Deployment Architecture 06-20-2011
2 1
2
1
dmlee
Hi , the case is about splunk deployment issue there is a deployment server and 20 deployment clients , we had finis...
by dmlee Communicator in Deployment Architecture 06-15-2011
0 1
0
1
gfriedmann
I am using the RPM package for splunk. I also utilize the "run splunk as splunk user" option. But there is a proble...
by gfriedmann Communicator in Deployment Architecture 06-15-2011
0 1
0
1
dmlee
During one of my searches, I got this following error message "unable to distribute to peer named splunk_index01 at u...
by dmlee Communicator in Deployment Architecture 06-14-2011
3 12
3
12
michaelgoodwin
Hi, We are trying to get HP-UX audit logs processed by Splunk. We get the logs in binary format, and run then throu...
by michaelgoodwin New Member in Deployment Architecture 06-10-2011
0 1
0
1
remy06
I've just upgrade a splunk server from 4.1.7 to 4.2.1. After the upgrade,I enabled the deployment monitor and notice...
by remy06 Contributor in Deployment Architecture 06-10-2011
0 1
0
1
dinisco
I have several hosts I want to deploy the same app to. I would like to use a different local/inputs.conf for differe...
by dinisco Explorer in Deployment Architecture 06-09-2011
0 1
0
1
Branden
According to the documentation: "To back up hot buckets as well, you need to take a snapshot of the files, using a to...
by Branden Builder in Deployment Architecture 06-08-2011
1 1
1
1
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...