Deployment Architecture

Deployment Architecture
Community Activity
hlarimer
I am using the metadata type=host command to alert me when a forwarder goes down and am now wanting to extend it to s...
by hlarimer Communicator in Deployment Architecture 11-12-2025
1 12
1
12
rayleigh29
Hi everyone,I’m currently planning to migrate an existing Splunk Enterprise All-in-One instance (Search Head + Indexe...
by rayleigh29 Explorer in Deployment Architecture 11-06-2025
0 1
0
1
Sam_Kurdy
Hello everyone,I have a small lab environment with one Windows Server (running Splunk Enterprise Trial) and three Win...
by Sam_Kurdy Engager in Deployment Architecture 11-03-2025
0 5
0
5
BrenDLSantos
Hi!Is it possible to deploy a local attack range with Ubuntu? I read from splunk github repo that running this locall...
by BrenDLSantos New Member in Deployment Architecture 10-23-2025
0 0
0
0
dexcare-techops
Hi all,I'm looking for a way to copy all of the logging from an index to an S3 bucket on my company account.Ideally, ...
by dexcare-techops Engager in Deployment Architecture 10-20-2025
0 3
0
3
_Raj
Hi,Please guide me how  to enable clustering (splunk enable cluster-master, splunk edit cluster-config) for one insta...
by _Raj Path Finder in Deployment Architecture 10-19-2025
0 5
0
5
andrewaalin
What is the significance of the list of fields in "search.log", in the line that contains "INFO LocalCollector - Fin...
by andrewaalin Explorer in Deployment Architecture 10-07-2025
3 2
3
2
zksvc
I encountered an issue where the Active Directory configuration, despite being set in attack_range.yml, failed to pro...
by zksvc Contributor in Deployment Architecture 10-05-2025
0 0
0
0
bapun18
Hi we wanted to migrate standalone indexer  to multisite cluster, with 2 site.Below are my questions1. Can I find out...
by bapun18 Communicator in Deployment Architecture 10-04-2025
0 2
0
2
maheshnc
Hello,Our operations team is supposed to perform OS Security patching on indexer cluster, search head, Heavy Forwarde...
by maheshnc Path Finder in Deployment Architecture 09-25-2025
0 3
0
3
maheshnc
I want to ingest syslog from different devices like ESXI Hosts, firewalls (fortigate, palo alto), switches can somebo...
by maheshnc Path Finder in Deployment Architecture 09-23-2025
0 9
0
9
MaverickT
I am posting this to maybe save you from few hours of troubleshooting like I did.I did clean install of Splunk 9.4 in...
by MaverickT Communicator in Deployment Architecture 09-22-2025
0 7
0
7
katelynengel
Is there a limit to how many Search Heads can be part of a Cluster? We have a fairly large deployment and I wanted t...
by katelynengel Explorer in Deployment Architecture 09-19-2025
1 8
1
8
zksvc
Hi all,I’m extracting fields from an event using the Field Extractor with a pipe (|) delimiter for sourcetype=alert:a...
by zksvc Contributor in Deployment Architecture 09-19-2025
0 3
0
3
ShawnXie
I have already deliver the splunk remote upgrader tgz ,with depoyment server.Can i deliver a script too to automatica...
by ShawnXie Loves-to-Learn in Deployment Architecture 09-17-2025
0 5
0
5
srek3502
Hi,I have a requirement to implement the Splunk Monitoring Console (DMC) in a High Availability (HA) setup. At presen...
by srek3502 Explorer in Deployment Architecture 09-10-2025
0 5
0
5
huynha
In my indexer cluster, one of my indexers has inflight files in the cold and warm storage that range from 1.5-2 month...
by huynha Explorer in Deployment Architecture 09-05-2025
1 4
1
4
DanAlexander
Why SC4S over a generic “syslog servers tier”1. It is Splunk’s best practice todaySplunk Validated Architectures call...
by DanAlexander Communicator in Deployment Architecture 09-03-2025
0 1
0
1
AliMaher
Hi I hope you are doing well. I have reinstalled the UF after that i found there are duplicate clients on the Deploym...
by AliMaher Path Finder in Deployment Architecture 08-28-2025
0 4
0
4
StephenD1
I have UFs in the DMZ and internal networks with a load balancer managing traffic between both zones. There is a sing...
by StephenD1 Path Finder in Deployment Architecture 08-25-2025
0 8
0
8
kevinhsu
Hello folks,We are doing splunkforwarder upgrade to 9.4.x (from 8.x) recently, we build the splunk sidecar image for ...
by kevinhsu New Member in Deployment Architecture 08-25-2025
0 1
0
1
zzhao05
This was the search head that kept failing: splunk > /appl/splunk/bin/splunk show shcluster-status -auth admin:admin...
by zzhao05 New Member in Deployment Architecture 08-11-2025
0 5
0
5
jkamdar
I have this small Splunk Enterprise deployment in a lab that's air gapped.So I setup this deployment about 18 months ...
by jkamdar Communicator in Deployment Architecture 08-06-2025
0 5
0
5
danielbb
What would be the proper way to deploy the TA_nix on the deployment server, is the reload option available or do I ne...
by danielbb Motivator in Deployment Architecture 08-05-2025
0 5
0
5
danielbb
I have two DSs that fail to deploy the TA_nix to themselves, how is it normally done? meaning how does the deployment...
by danielbb Motivator in Deployment Architecture 08-04-2025
0 6
0
6
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...