Deployment Architecture

Deployment Architecture
Community Activity
logtastic
I've read all the suggestion on importing bash history logs and tried variation of fschange, followTail and ignoreOld...
by logtastic Explorer in Deployment Architecture 08-19-2021
0 0
0
0
Tara
Is that correct that Splunk add-on builder v4.0.0:sets read/write permissions for add-on's files. "execute" permissio...
by Tara Loves-to-Learn Lots in Deployment Architecture 08-18-2021
0 0
0
0
govindashwin8
I have created a new cluster with a Master, a search head, indexers and forwarders, similar to the architecture here ...
by govindashwin8 Loves-to-Learn Lots in Deployment Architecture 08-18-2021
0 10
0
10
ialahdal
I have a SHC consisting of 3x SHs with https enabled.are there any steps I need to do from Splunks end to enable a sp...
by ialahdal Path Finder in Deployment Architecture 08-18-2021
0 1
0
1
yousefhawwari
Dears,Hope you're doing great.Please note that the Splunk indexer is not booting but other servers is booting and wor...
by yousefhawwari Loves-to-Learn in Deployment Architecture 08-17-2021
0 2
0
2
Wojt3k
Hello,I would like to exclude just one user from forwarding logs and I am thinking if my solution will work:in inputs...
by Wojt3k Engager in Deployment Architecture 08-16-2021
0 2
0
2
PickleRick
I'm reading the docs about sharing summaries between search-heads and I'm a bit puzzled.https://docs.splunk.com/Docum...
by SplunkTrust SplunkTrust in Deployment Architecture 08-13-2021
0 2
0
2
ips_mandar
Hi, I am getting below error for '_introspection' index- The percentage of small buckets (75%) created over the last...
by ips_mandar Builder in Deployment Architecture 08-12-2021
0 4
0
4
syedabuthahir
Hi All, We are trying to push the props and transforms config files from Cluster Master to all indexers. Source types...
by syedabuthahir Explorer in Deployment Architecture 08-12-2021
0 2
0
2
nwales
As above, I kicked off an update and the cluster master is stuck at "Bundle validation is in progress" and has been f...
by nwales Path Finder in Deployment Architecture 08-12-2021
2 13
2
13
gots
We have search head splunk cluster. After upgrade to 8.0.1 from 7.2.6 we began to get errors like: "12-18-2019 16:47:...
by gots Path Finder in Deployment Architecture 08-11-2021
0 9
0
9
sarvesh_11
Hello Splunkers.We want to deploy a splunk product in our environment, to monitor Infrastructure along with some Auto...
by sarvesh_11 Communicator in Deployment Architecture 08-11-2021
0 3
0
3
ft_kd02
Hi all, not sure if deployment architecture was the right place to put this question. I need some clarification regar...
by ft_kd02 Path Finder in Deployment Architecture 08-09-2021
0 2
0
2
Jarohnimo
Hello,I have a test environment and the SHC members aren't allocated the recommended resources (because it's test) ho...
by Jarohnimo Builder in Deployment Architecture 08-07-2021
0 1
0
1
coltwanger
We've currently got just one DS in our environment handling about 1100 forwarders. Performance has been pretty stable...
by coltwanger Contributor in Deployment Architecture 08-06-2021
2 8
2
8
akash99
Hello,I've below configuration for one index.maxTotalDataSizeMB = 333400maxDataSize = auto_high_volumehomePath = volu...
by akash99 Loves-to-Learn in Deployment Architecture 08-03-2021
0 1
0
1
andymalato
Hello All, We have an index cluster which utilizes SmartStore in AWS S3.  Things appear to be working but we have obs...
by andymalato Explorer in Deployment Architecture 08-03-2021
0 0
0
0
johng2006
Whenever I try to open Splunk from a masked URL (a URL that points to a URL but shows the first URL in the browser se...
by johng2006 New Member in Deployment Architecture 08-02-2021
0 0
0
0
osasfrancis
We are in the process of migrating a lot of hosts to report to a new deployment server. The deploymentclient.conf fil...
by osasfrancis Path Finder in Deployment Architecture 08-02-2021
0 6
0
6
data_beast
Hi Splunkers, While splunking on bucket statistics - I've noticed that despite the fact of default 90 days set for ma...
by data_beast Explorer in Deployment Architecture 08-02-2021
0 0
0
0
dhirendra761
Hi,is it possible to indexed the event only once. Thank you in advance.
by dhirendra761 Contributor in Deployment Architecture 07-29-2021
0 3
0
3
andymalato
Hello All,We currently have a single standalone deployment (index and search head on single system).  In addition, we...
by andymalato Explorer in Deployment Architecture 07-29-2021
0 2
0
2
bk
We are running Splunk on Windows and are moving from a multisite cluster with two sites to a single site. Are there a...
by bk Engager in Deployment Architecture 07-27-2021
1 1
1
1
tarokker
Dear Splunk community,I received an alert mail  from Splunk about the need to update my splunkbase app with latest ad...
by tarokker New Member in Deployment Architecture 07-27-2021
0 0
0
0
splunkreal
Hello guys,how do you handle missing forwarders (deleted VMs for instance)?Do you go to "Forwarder management" then "...
by splunkreal Motivator in Deployment Architecture 07-26-2021
0 5
0
5
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...
Top Solution Authors