Deployment Architecture

Deployment Architecture
Community Activity
muez
I have 10 SH in my environment.(THEY ARE NOT under SEARCH HEAD CLUSTERING) but they are under my master's "list of pe...
by muez Explorer in Deployment Architecture 01-10-2020
0 2
0
2
abhirajpawar
In my environment I had one serverclass in deployment server, which had neither any client nor app. I deleted this se...
by abhirajpawar New Member in Deployment Architecture 01-09-2020
0 0
0
0
sudeshgaur
I want to setup a script to delete frozen data that older than 36 months. If I run the script to delete data from one...
by sudeshgaur New Member in Deployment Architecture 01-09-2020
0 4
0
4
Balajiraj
I have a query which looks for date and time in a field(Timestamp) which is of format "Wed Jan 01 16:24:28 EST 2020" ...
by Balajiraj Explorer in Deployment Architecture 01-09-2020
0 9
0
9
ips_mandar
Hi I am using Splunk on Windows OS and I want to store hot/warm buckets on local storage and cold buckets on flash sh...
by ips_mandar Builder in Deployment Architecture 01-09-2020
0 6
0
6
kishor_pinjarka
Why I am not able to see Search Heads connection in Cluster Master Monitoring Console - Overview Dashboard (See 1st i...
by kishor_pinjarka Path Finder in Deployment Architecture 01-08-2020
0 5
0
5
troyfred
Hello, So I have a rather unique issue that I am really having trouble with. We have a client that has their own spl...
by troyfred Explorer in Deployment Architecture 01-08-2020
0 0
0
0
bhavin_crest
I'm trying to set a SHC ,but I'm ended up by creating SHC which is having one member and which is captain my other tw...
by bhavin_crest Explorer in Deployment Architecture 01-08-2020
0 3
0
3
rupeshn
Hi , 1.Could you please let me know if one of the indexers in Single site Clustering be made as Cluster master? Is ...
by rupeshn Explorer in Deployment Architecture 01-07-2020
0 4
0
4
jk01571
Indexer '/splunk/var/run/splunk/cluster/search-buckets/ ' Files are still piled up. What is the purpose of the file?...
by jk01571 New Member in Deployment Architecture 01-07-2020
0 0
0
0
sparrowe
Hello, I was hoping for some additional thoughts, after I updated my Search Head to use custom certs I started getti...
by sparrowe Explorer in Deployment Architecture 01-07-2020
1 8
1
8
bhavin_crest
Can some one pleace explain me the replation between Replication Fector and Search Artifact.
by bhavin_crest Explorer in Deployment Architecture 01-07-2020
0 3
0
3
palisetty
Hello, Now that I am done with the exam, I want to explain Splunk Architecture in my own understanding elements. Kind...
by palisetty Communicator in Deployment Architecture 01-07-2020
0 1
0
1
sudhir7
I have two indexers in my Splunk environment running in the cluster mode. After upgrading the Splunk cluster from ver...
by sudhir7 Explorer in Deployment Architecture 01-07-2020
0 1
0
1
bhavin_crest
How can I figure out that in established SHC showing captain is static or dynamic, using CLI or .conf files? I mean w...
by bhavin_crest Explorer in Deployment Architecture 01-07-2020
0 1
0
1
platformred
We're using the docker images at https://hub.docker.com/r/splunk/splunk to install splunk in kubernetes. We're curren...
by platformred Explorer in Deployment Architecture 01-07-2020
2 9
2
9
rupeshn
Hi Planning to migrate data from current environment to future environment! Current = (One search head + one indexe...
by rupeshn Explorer in Deployment Architecture 01-05-2020
0 1
0
1
jg91
Hello friends, We want to deploy splunk in a new site and we have 2 powerful server with SSD storage, We need to have...
by jg91 Path Finder in Deployment Architecture 01-03-2020
0 2
0
2
VijaySrrie
Hi, Logs after indexing is sent to Search head. We have below settings Searchable Time (days) = 90 days Archieve R...
by VijaySrrie Builder in Deployment Architecture 01-03-2020
0 1
0
1
stonera15
I receive the above error. I'm trying to monitor a directory from my local computer (UF installed) and checking the o...
by stonera15 New Member in Deployment Architecture 01-02-2020
0 1
0
1
jonsplunktriral
Hello Everyone, I was using Splunk Enterprise and my license had expired but I still want to have additional inputs ...
by jonsplunktriral New Member in Deployment Architecture 01-02-2020
0 3
0
3
ronlevytn
When the deployer sends a restart with /opt/splunk/bin/splunk restart, that changes the value I get with systemctl st...
by ronlevytn Engager in Deployment Architecture 12-31-2019
1 1
1
1
janglin
What is the point of the "splunk enable boot-start" enabling then immediately disabling the service at boot-start? c...
by janglin Explorer in Deployment Architecture 12-31-2019
0 5
0
5
davidemagni
Hi all, we are experiencing problem with the Deployment Server after the 7.2.3 release. The Universal Forwarder is in...
by davidemagni Explorer in Deployment Architecture 12-31-2019
0 1
0
1
pratapa
How can I check whether the data from a server is being forwarded to indexer.
by pratapa Explorer in Deployment Architecture 12-31-2019
0 3
0
3
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Solution Authors