Hi everyone,
i am new to splunk and i am setting it up in our staging and production envs, i would like to know how i could manage this situation
We have something like 30 partners each of them with a bunch of vms, each containing the partner name in the hostname. All of them pointing to the same indexers cluster.
What i would like to do is to search only for a specific partner and get back all results from all its VMs.
I can search:
host=*partnername*
but i am wondering if it's a better idea to create an index with the partner name and set it in each vm.
Or maybe i can create a specific field instead of an index?
The purpose of creating a new index is for retention and security. If each partner has the ability to search the data and you don't want them to look at each others data OR if they have different retention requirements then yes, you should create separate indexes for each partner. If the conditions I laid out above are not true, then you can leave them in the same index
If you decide to go the ladder route, you should create an eventtype for each partner so its easy to search
The purpose of creating a new index is for retention and security. If each partner has the ability to search the data and you don't want them to look at each others data OR if they have different retention requirements then yes, you should create separate indexes for each partner. If the conditions I laid out above are not true, then you can leave them in the same index
If you decide to go the ladder route, you should create an eventtype for each partner so its easy to search
They don't have access to our logs.
It's internal just for us. And what i want to do it's just to make a partner's log easier to find.
Great, then you should put it into a single index. You'll use more storage if you have separate indexes due to the additional tsidx files generated
You should create eventtypes for each partner or tag their host to make it easy to find. If this answered your question, can you please accept it to close it out?
yes perfect thanks!