Installation

How to find out what we selected on installation of Splunk when it comes to sending data to Splunk?

AndreaSimon
New Member

We inherited Splunk from another team and my leadership wants to know if when Splunk was installed, if we opted out of sending information to Splunk. Is there a way to find out what the original installer selected for this option? I have not installed splunk so I am unsure if it even asks you if you want to opt out of sending splunk information to them.

0 Karma

pwilliams_splun
Splunk Employee
Splunk Employee

I found this in the docs for 7.1.1:

The instrumentation feature adds an
internal index and can increase disk
space usage (Originally introduced in
version 6.5)

The instrumentation feature of Splunk
Enterprise, which lets you share
Splunk Enterprise performance
statistics with Splunk after you opt
in, includes a new internal index
which can cause disk space usage to
rise on hosts that you upgrade. You
can opt out of sharing performance
data by following the instructions at
Share data in Splunk Enterprise in the
Admin Manual.

It appears that if you opt-in, since version 7.0, you will send license usage data by default.

0 Karma

pradeepkumarg
Influencer

Go to settings - > instrumentation

Click on the settings icon next to usage data to see what is turned on.

More details here
http://docs.splunk.com/Documentation/Splunk/7.1.1/Admin/Shareperformancedata

0 Karma

AndreaSimon
New Member

I should have said this in the original post, we are on 6.3.3. I don't have Settings -> Instrumentation when logged in as admin.

0 Karma

pradeepkumarg
Influencer

Documentation says "For the usage data logs to be created and available, your search heads, indexers, and cluster master must be running Splunk Enterprise version 6.5.0 or later."
So it might be a case that there is no collection prior to 6.5. I could be wrong.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...