Deployment Architecture

Deployment Architecture
Community Activity
yoho
When configuring data inputs on a heavy forwarder via the GUI (HEC, for instance), the destination index is requested...
by yoho Contributor in Deployment Architecture 06-08-2021
0 6
0
6
dkr3500
I stood up a new set of indexers this weekend and set my RF=2 and SF=1 on the CM with the hope that the old indexers ...
by dkr3500 Path Finder in Deployment Architecture 06-07-2021
0 2
0
2
dc595
HI Team,Today we have a 4 index cluster and we want to create a separate index cluster that does not share configurat...
by dc595 Explorer in Deployment Architecture 06-04-2021
0 1
0
1
termcap
Hi,Considering that the deployment server, Search Heads, Universal Forwarder and Deployers are full Splunk Enterprise...
by termcap Path Finder in Deployment Architecture 06-04-2021
0 1
0
1
tk111
With Splunk for Windows and Splunk Enterprise Security. Are there specific periodic maintenance tasks that need to be...
by tk111 Engager in Deployment Architecture 06-03-2021
0 3
0
3
anil1432
We want to work on some cost calculation by counting the number of characters per line and grouping the size per cust...
by anil1432 Explorer in Deployment Architecture 06-01-2021
0 2
0
2
danielbb
Half of the eight indexers will be off for potentially a day, so we'll have four indexers available for that time. Ou...
by danielbb Motivator in Deployment Architecture 06-01-2021
0 1
0
1
termcap
Hi,I have the following outputs.conf on my Splunk Heavy Forwarder: defaultGroup = indx1 [tcpout:indx1] server=1.1.1....
by termcap Path Finder in Deployment Architecture 05-31-2021
0 4
0
4
jcorcoran508
I inherited a one SH and 2 indexers , 1 LM, one Deployment server supporting forwarders.I have too on board data  and...
by jcorcoran508 Path Finder in Deployment Architecture 05-28-2021
0 3
0
3
chiennylin
Good day!I want to know if it's possible to use splunk as a recovery option?this means that Splunk will be sending me...
by chiennylin New Member in Deployment Architecture 05-27-2021
0 0
0
0
ipl
Hello!We have two offices: Head and Branch. The Head office has a Splunk infrastructure (Enterprise Security), which ...
by ipl New Member in Deployment Architecture 05-26-2021
0 1
0
1
mosmond
We have been getting messages about high percentage of small buckets.  I set logging to DEBUG on one of our indexers ...
by mosmond Engager in Deployment Architecture 05-24-2021
1 3
1
3
arielpconsolaci
Hi Splunkers,Good day. My HEC tokens are currently configured in the Indexer Cluster, and during Indexer Bundle Push ...
by arielpconsolaci Path Finder in Deployment Architecture 05-23-2021
0 0
0
0
Dograv
One of our customer is looking to setup a SOC with a SIEM solution and they want to monitor and manage multiple PCI z...
by Dograv New Member in Deployment Architecture 05-21-2021
0 1
0
1
yuanliu
In order to perform fast Fourier transform (FFT), I need data from equal time intervals. Here is my first attempt: |...
by SplunkTrust SplunkTrust in Deployment Architecture 05-21-2021
1 17
1
17
ahartge
I have noticed something odd in a SHC deployment. Im consistently seeing "SHCMasterArtifactHandler - failed on handle...
by ahartge Path Finder in Deployment Architecture 05-20-2021
2 3
2
3
d_lim
Hi splunk community,In my environment I have 1 indexer each in 2 different datacenters, 1 searchhead, 1 clustermaster...
by d_lim Path Finder in Deployment Architecture 05-20-2021
0 0
0
0
sylim_splunk
pushed apps to the search head cluster to 3 Searchheads 2 of them working good but one searched URL is not accessible...
by sylim_splunk Splunk Employee Splunk Employee in Deployment Architecture 05-19-2021
0 1
0
1
snsaxena
I can see that we are having duplicate events in every index, query used to identify the duplicate events:index=* |ev...
by snsaxena Loves-to-Learn Lots in Deployment Architecture 05-19-2021
0 0
0
0
sarvesh_11
Hello Splunkers!Wish You are safe and healthy from this pandemic.I am using Splunk 8.0 Version, because it gives the ...
by sarvesh_11 Communicator in Deployment Architecture 05-18-2021
0 7
0
7
dave_null
Hello, I have an on-prem Splunk cluster and an AWS cluster. Each one has its own indexers and clustermaster, though o...
by dave_null Path Finder in Deployment Architecture 05-18-2021
0 0
0
0
shreya17
I am getting an error **"Search auto-canceled"**  after upgrading to OEL7 on search file.05-18-2021 14:15:40.913 INFO...
by shreya17 Explorer in Deployment Architecture 05-17-2021
1 0
1
0
rbal_splunk
This question has come up a few times, how does Splunk handle data integrity in large ES implementation. On Splunk do...
by rbal_splunk Splunk Employee Splunk Employee in Deployment Architecture 05-14-2021
0 2
0
2
scheckenbachb
We had to restore the Splunk indexer from a backup, loosing the 'colddb'. I now see the folowing ERROR in splunk.log,...
by scheckenbachb Explorer in Deployment Architecture 05-13-2021
0 2
0
2
muebel
When an indexer is restarted during a normal rolling restart, does it shutdown via the `offline` method? Or does it d...
by SplunkTrust SplunkTrust in Deployment Architecture 05-11-2021
0 0
0
0
Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...