Deployment Architecture

Deployment Architecture
Community Activity
payal23
Hi, I have audit data coming from a port (UDP) to Heavy Forwarder[via syslog] and have to apply rlog.sh on the same....
by payal23 Path Finder in Deployment Architecture 02-20-2020
0 3
0
3
samadmemon
Hi All, I am trying to build a query through which we can track if all the Splunk forwarders are connected to Cluste...
by samadmemon Explorer in Deployment Architecture 02-18-2020
0 7
0
7
aojie654
Hi, splunkers: Is there any way to special the storage ratio? Like 30% log store on indexer A and the other 70% sto...
by aojie654 Path Finder in Deployment Architecture 02-17-2020
0 4
0
4
ctaf
Hi, We would like to use the same Data Model (same field extractions, same events, same acceleration window, etc.) i...
by ctaf Contributor in Deployment Architecture 02-17-2020
1 4
1
4
secuc2r83
Hi, I have 2 independent Search Heads (SH) (no clustering) and they use the same indexers. On the first SH: I have...
by secuc2r83 Path Finder in Deployment Architecture 02-17-2020
0 10
0
10
AbilashSe
Search heads are up and healthy, but there is a fluctuation in the Search head status in the indexer clustering. Can...
by AbilashSe Explorer in Deployment Architecture 02-17-2020
0 5
0
5
jbruce506
Here's the situation - we have a non-developer, new to Splunk, without access to Hadoop (or any basic understanding o...
by jbruce506 Explorer in Deployment Architecture 02-16-2020
0 1
0
1
tberres1987
Environment: Splunk version: 7.2.5 Distributed deployment with multiple Heavy Forwarders managed by Deploymentserver....
by tberres1987 New Member in Deployment Architecture 02-15-2020
0 1
0
1
brent89567
I have a setup right now where we have 1 indexer in our test environment and we are putting 2 new indexers in the pro...
by brent89567 New Member in Deployment Architecture 02-15-2020
0 2
0
2
mjltls
I want to add the app Splunk Dashboard examples to my 7.01 environment. As soon as I select find new apps I get the e...
by mjltls New Member in Deployment Architecture 02-14-2020
0 1
0
1
afolabia
My Cisco Indexer just stopped indexing new data. Splunk is receiving data from the Syslog server but just not getting...
by afolabia Path Finder in Deployment Architecture 02-13-2020
0 4
0
4
icehawk55
I've been poking around the interwebs trying to figure out if there is a benefit/downside to going with the new AMD R...
by icehawk55 New Member in Deployment Architecture 02-13-2020
0 1
0
1
saurabh0912
Hi, Wanted to know if there could be any impact on performance of a search head, if we add many indexer peer to a sin...
by saurabh0912 Path Finder in Deployment Architecture 02-13-2020
0 3
0
3
lyndac
I currently have a Splunk environment that consists of: 1 License Manager/Deployment Server 1 Search Head 2 Indexers ...
by lyndac Contributor in Deployment Architecture 02-12-2020
0 2
0
2
woodcock
We have a not-at-all overloaded ES search head with a separate volume for dispatch with plenty of room that gives us ...
by Esteemed Legend in Deployment Architecture 02-12-2020
0 1
0
1
duke_splunk_adm
After several years the replication factor on my 6.6.3 index cluster recently changed to 'not met'. it has been fine...
by duke_splunk_adm Engager in Deployment Architecture 02-11-2020
0 4
0
4
efaundez
Good afternoon    Is there splunk documentation where it is reported that in a SHC the servers must be certified at ...
by efaundez Path Finder in Deployment Architecture 02-11-2020
0 5
0
5
bsuresh1
I am using Splunk Cloud environment. I am interested to know how many buckets created for an index and what will be d...
by bsuresh1 Path Finder in Deployment Architecture 02-11-2020
0 1
0
1
mark_wymer
Hi all, Our environment consists of, amongst other things, a multisite (3) clustered environment. Each site has thre...
by mark_wymer Path Finder in Deployment Architecture 02-11-2020
0 2
0
2
yuanliu
I have two dashboards with custom drilldown search. One of them works just fine. But the other returns a blank page...
by SplunkTrust SplunkTrust in Deployment Architecture 02-10-2020
0 2
0
2
anandhalagaras1
Hi Team, We were using Splunk Enterprise for last few years. And recently by May 2019 we have migrated all the data ...
by anandhalagaras1 Contributor in Deployment Architecture 02-10-2020
0 6
0
6
nishida_tada_ca
After importing DBConect data, Although the rentention of the index is a day ago, It is kept for 5 days. Does splunk ...
by nishida_tada_ca Loves-to-Learn Lots in Deployment Architecture 02-10-2020
0 1
0
1
RK_sp1unk
Issue:Unable to add search peer from search head using distributed search :no route to host or connection refused err...
by RK_sp1unk New Member in Deployment Architecture 02-09-2020
0 3
0
3
kjstogn
I have a single indexer and single search head with the indexer attached as a search peer and I created one index cal...
by kjstogn Explorer in Deployment Architecture 02-08-2020
0 1
0
1
DEAD_BEEF
Using Splunk 7.3.3, after I initiated a rolling restart from the cluster master (multi-site indexer cluster), the fi...
by DEAD_BEEF Builder in Deployment Architecture 02-08-2020
1 6
1
6
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...