Splunk Search

about metrics.log:name

HiroshiSatoh
Champion

What is the last value of name in metrics.log?

name=default-autolb-group:172.01.01.01:9997:0
name=default-autolb-group:172.01.01.01:9997:1

What does (0 OR 1) mean?

Tags (1)
0 Karma
1 Solution

mattymo
Splunk Employee
Splunk Employee
<mythbusted>I believe it denotes pipelines when parallelization is being used <\mythbusted>

EDIT: My bad, I was thinking of Ingest_pipe=*

The number on the end of the name appears to be an index of all the unique receivers in that group

name is a combination of conf stanza and entries that fully define the target system to the software.

https://docs.splunk.com/Documentation/Splunk/6.5.2/Troubleshooting/Aboutmetricslog#Tcpout_Connection...

My tcpout_connection entry looks like this:

name=default-autolb-group:10.10.31.83:9997:0

because the default-autolb-group only contains one indexer.....will add another and confirm

In your example do the numbers match the amount of unique indexers?

- MattyMo

View solution in original post

0 Karma

mattymo
Splunk Employee
Splunk Employee
<mythbusted>I believe it denotes pipelines when parallelization is being used <\mythbusted>

EDIT: My bad, I was thinking of Ingest_pipe=*

The number on the end of the name appears to be an index of all the unique receivers in that group

name is a combination of conf stanza and entries that fully define the target system to the software.

https://docs.splunk.com/Documentation/Splunk/6.5.2/Troubleshooting/Aboutmetricslog#Tcpout_Connection...

My tcpout_connection entry looks like this:

name=default-autolb-group:10.10.31.83:9997:0

because the default-autolb-group only contains one indexer.....will add another and confirm

In your example do the numbers match the amount of unique indexers?

- MattyMo
0 Karma

HiroshiSatoh
Champion

Hi, mmodestino
I thought so, but there are obviously more numbers than pipeline number.

0 Karma

mattymo
Splunk Employee
Splunk Employee

what do you mean?
do you not have parallelization turned on?

- MattyMo
0 Karma

mattymo
Splunk Employee
Splunk Employee

ah I see what you mean...updating answer

- MattyMo
0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...