Deployment Architecture

Deployment Architecture
Community Activity
travislelledeep
What would be considered the Splunk best practice when managing multiple deployment servers in different locations th...
by travislelledeep Explorer in Deployment Architecture 01-25-2021
0 3
0
3
ravi
I have an add on  installed in Deployer which has been configured with Credentials and is working fine. But when i se...
by ravi Loves-to-Learn Lots in Deployment Architecture 01-21-2021
0 1
0
1
X_Kinkead
I'm looking for advice for avoiding the 'Funnel Effect' for a small number of intermediate Universal Forwarders to ab...
by X_Kinkead Explorer in Deployment Architecture 01-21-2021
0 2
0
2
DawidM
I want to set up the retention policy for our logs (18 months). I have edited the indexes.conf to specify frozenTimeP...
by DawidM Explorer in Deployment Architecture 01-21-2021
0 5
0
5
halbeisendv
I have a Splunk instance that I'm using as a deployer called halfiron. I created user-prefs.conf in this directory. (...
by halbeisendv Path Finder in Deployment Architecture 01-20-2021
0 11
0
11
lucacaldiero
Hi all,I have an architecture with a search head cluster (3 members) and and 2 indexers, that are not in cluster.Whic...
by lucacaldiero Path Finder in Deployment Architecture 01-19-2021
0 2
0
2
edgarsilva01
Hello everyoneI need help to send information to 2 indexers.By request of the client I need to send information from ...
by edgarsilva01 Path Finder in Deployment Architecture 01-19-2021
0 2
0
2
sting663
Hello there,Is there any way to either configure an alert when the heavy forwarders are not sending logs in splunk cl...
by sting663 New Member in Deployment Architecture 01-18-2021
0 1
0
1
efika
Please assume the below in transforms.conf[send_rawevents] REGEX = . DEST_KEY = _TCP_ROUTING FORMAT = indexer1 [send...
by efika Communicator in Deployment Architecture 01-18-2021
0 0
0
0
phil_wong
What's the meaning of this warning message?I didn't enable index reduction at all."Search on most recent data has com...
by phil_wong Explorer in Deployment Architecture 01-17-2021
0 3
0
3
bhupalbobbadi
Anybody have faced this issue?$ /opt/splunk/bin/splunk add shcluster-memberDeserialization failed. Could not find exp...
by bhupalbobbadi Path Finder in Deployment Architecture 01-17-2021
0 1
0
1
rahulhari88
Hi All , We have 1 indexer, 1 SH and 1 DS . We are  planning for an OS upgrade (OS RHEL 6 to OL 7)  .All the these de...
by rahulhari88 Explorer in Deployment Architecture 01-15-2021
0 1
0
1
cirkit1
We are having an issue with our Splunk installation not being able to run any searches on our Test environment. We s...
by cirkit1 Explorer in Deployment Architecture 01-15-2021
0 3
0
3
mchang_splunk
We migrate single site to multisite cluster by following the document: https://docs.splunk.com/Documentation/Splunk/l...
by mchang_splunk Splunk Employee Splunk Employee in Deployment Architecture 01-15-2021
0 2
0
2
rafaelruales
Good Morning,I wanted to ask about something I have read somewhere, but not entirely sure. I am a beginner in Splunk ...
by rafaelruales Explorer in Deployment Architecture 01-14-2021
0 3
0
3
lenorxav
Hello, I'm having an issue with maxming GeoLite database update. Even I'm updating the database on Splunk the Count...
by lenorxav Explorer in Deployment Architecture 01-14-2021
0 4
0
4
splunkreal
Hello,our architecture in production was created years ago, we have Deployment Server and Cluster Master on same mach...
by splunkreal Motivator in Deployment Architecture 01-13-2021
0 4
0
4
Thighcep
Seeing an issue in our environment - we have a search head cluster and the captain throws the following error message...
by Thighcep Loves-to-Learn Lots in Deployment Architecture 01-13-2021
0 0
0
0
marcelb
I have tested the S3 compatibility of MinIO with the tool(https://github.com/splunk/s3-tests). Some of the tests fail...
by marcelb New Member in Deployment Architecture 01-13-2021
0 0
0
0
csahu
How can i integrate my windows web server IIS logs to splunk. I am planning to setup lab for splunk by using windows ...
by csahu Observer in Deployment Architecture 01-10-2021
0 1
0
1
DataOrg
i have newly installed UF on the linux machine and splunk user/groups created.afterwards pushed apps from the deploym...
by DataOrg Builder in Deployment Architecture 01-08-2021
0 3
0
3
Ed11375
Can Splunk Web in a Splunk Enterprise solution be hosted on a server other than the Splunk Search Head? We are curren...
by Ed11375 Explorer in Deployment Architecture 01-08-2021
0 2
0
2
splunktrainingu
Hello  I created an app, and now I am trying to figure out the  permissions it needs because it is getting deployed o...
by splunktrainingu Communicator in Deployment Architecture 01-07-2021
0 2
0
2
SS1
Hi SPlunkers,Currently we have a single instance deployment i.e. we have a splunk enterprise console which has both i...
by SS1 Path Finder in Deployment Architecture 01-07-2021
0 1
0
1
chustar
While reading the guide for upgrading stand alone search heads to a cluster, I noticed that you cannot add an existin...
by chustar Path Finder in Deployment Architecture 01-06-2021
1 2
1
2
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...
Top Solution Authors