Deployment Architecture

Deployment Architecture
Community Activity
sanju005ind
I have 8 Indexers in my environment.I would like to keep the configurations especially the props.conf and the Transfo...
by sanju005ind Communicator in Deployment Architecture 11-30-2010
0 5
0
5
olopez77
What are the CLI commands to configure Windows event log (Application, Security, System) monitoring on a light forwar...
by olopez77 Explorer in Deployment Architecture 11-30-2010
1 2
1
2
Starlette
My coldtofrozenscript on linux is totaly ignored, I tweaked the indexes.conf (a few warmbuckets and small total index...
by Starlette Contributor in Deployment Architecture 11-29-2010
0 4
0
4
hulahoop
We are seeing these messages in splunkd.log: 07-29-2010 14:26:34.729 ERROR databasePartitionPolicy - unable to open ...
by hulahoop Splunk Employee Splunk Employee in Deployment Architecture 11-19-2010
1 6
1
6
mburbidg
I'm setting up splunk and have a configuration where I have a single machine for indexing and searching. I have a han...
by mburbidg Explorer in Deployment Architecture 11-18-2010
0 1
0
1
sdevadas
I keep getting these in the logs for a particular client where we have setup a scripted input which delivers the data...
by sdevadas Path Finder in Deployment Architecture 11-18-2010
2 2
2
2
castle1126
Hi, I'm in the process of taking some of my indexes and moving them to a new server. Currently both servers are up a...
by castle1126 Communicator in Deployment Architecture 11-17-2010
2 5
2
5
sdaa
It's possible from 4.1.5 to roll over indexes manually with ./splunk _internal call /data/indexes/<index_name>/roll-h...
by sdaa Explorer in Deployment Architecture 11-15-2010
2 2
2
2
tier2ops
So I have two ha pairs that I want to set distributes searches on: Pair-A-1 10.10.10.5 Pair-A-2 10.10.10.6 VIP 10....
by tier2ops Explorer in Deployment Architecture 11-12-2010
1 1
1
1
djfisher
I noticed after an internal audit that Splunk is not forwarding the entire audit.log. I am using Linux Redhat 5. All...
by djfisher Explorer in Deployment Architecture 11-09-2010
0 4
0
4
snapfinger
What are the ports that i need to have open for using the deployment options with my splunk server. My main install...
by snapfinger Engager in Deployment Architecture 11-08-2010
0 1
0
1
sgwambe
I am running windows server 2003 on my Site but is has been rebooting itself the whole day i need help
by sgwambe New Member in Deployment Architecture 11-06-2010
0 3
0
3
Chris_R_
How do i manually roll buckets in 4.1? The old method ./splunk search "| debug cmd=roll index=main" does not...
by Chris_R_ Splunk Employee Splunk Employee in Deployment Architecture 10-29-2010
4 7
4
7
nhsplunk
I went through Manager -> Data Inputs -> Files & Directories and chose "Monitor a file or directory" option. I entere...
by nhsplunk New Member in Deployment Architecture 10-29-2010
0 2
0
2
anantshah
Hello, We are on Splunk 4.1.3. We have configured light forwarders on 4 windows 2008 r2 servers to send IIS logs to ...
by anantshah Path Finder in Deployment Architecture 10-28-2010
1 6
1
6
Jason
Say I use deployment server to deploy an App (with user interface) to a search head, and a user uses it, creates a se...
by Jason Motivator in Deployment Architecture 10-27-2010
1 1
1
1
Jason
Say I have two indexers in two different datacenters, and I want to distribute searches across the WAN/VPN/Internet b...
by Jason Motivator in Deployment Architecture 10-26-2010
1 3
1
3
asmercer2004
I am trying to use splunk to pull event logs from computers on the domain and archive them. I installed it on one ma...
by asmercer2004 Explorer in Deployment Architecture 10-20-2010
0 5
0
5
cbse120109
I will have two Splunk Servers, one called Central and the other Remote. Remote will have a 1 week retention and be u...
by cbse120109 Explorer in Deployment Architecture 10-17-2010
2 9
2
9
asmercer2004
I am using splunk to pull the event log data off several machines on a domain and archive them on a single server. I...
by asmercer2004 Explorer in Deployment Architecture 10-13-2010
0 5
0
5
Jason
I'm trying to pull a random item from a set of splunk data, so to test I have set up this simple search: index="_int...
by Jason Motivator in Deployment Architecture 10-12-2010
1 7
1
7
rotten
All other things being equal, would we see any performance gains with Splunk if we switch our file system from ext3 t...
by rotten Communicator in Deployment Architecture 10-08-2010
1 2
1
2
dpkdshp
Hi, In our environment we have configured the Splunk Light Forwarder to monitor a log file and forward raw data form...
by dpkdshp New Member in Deployment Architecture 10-08-2010
0 4
0
4
meatago
I'm using a lightweight forwarder installed on Ubuntu to forward snort alerts to my main splunk server. On the main ...
by meatago Explorer in Deployment Architecture 10-08-2010
0 6
0
6
matt
I've got a distributed search setup (standalone search head and an indexer) that has been working like a champ for aw...
by matt Splunk Employee Splunk Employee in Deployment Architecture 10-07-2010
1 1
1
1
Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...