Getting Data In

How often does the search head send the knowledge bundles to the indexers?


My indexer has /opt/splunk/var/run/searchpeers.
How often do searchpeers get updated?
I also have an old backup searchpeers.bak which is occupying space.
So, can I remove searchpeers.bak?


Haven't deleted that info, but I think it would
get replicated again...since bundle won't get overwritten when
Splunk is upgraded.

you can reduce the size of the bundle by means of the
[replicationWhitelist] or [replicationBlacklist] stanza in
distsearch.conf . See "Modify the knowledge bundle" in the deployment manual.

0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...