Splunk Search

about metrics.log:name

HiroshiSatoh
Champion

What is the last value of name in metrics.log?

name=default-autolb-group:172.01.01.01:9997:0
name=default-autolb-group:172.01.01.01:9997:1

What does (0 OR 1) mean?

Tags (1)
0 Karma
1 Solution

mattymo
Splunk Employee
Splunk Employee
<mythbusted>I believe it denotes pipelines when parallelization is being used <\mythbusted>

EDIT: My bad, I was thinking of Ingest_pipe=*

The number on the end of the name appears to be an index of all the unique receivers in that group

name is a combination of conf stanza and entries that fully define the target system to the software.

https://docs.splunk.com/Documentation/Splunk/6.5.2/Troubleshooting/Aboutmetricslog#Tcpout_Connection...

My tcpout_connection entry looks like this:

name=default-autolb-group:10.10.31.83:9997:0

because the default-autolb-group only contains one indexer.....will add another and confirm

In your example do the numbers match the amount of unique indexers?

- MattyMo

View solution in original post

0 Karma

mattymo
Splunk Employee
Splunk Employee
<mythbusted>I believe it denotes pipelines when parallelization is being used <\mythbusted>

EDIT: My bad, I was thinking of Ingest_pipe=*

The number on the end of the name appears to be an index of all the unique receivers in that group

name is a combination of conf stanza and entries that fully define the target system to the software.

https://docs.splunk.com/Documentation/Splunk/6.5.2/Troubleshooting/Aboutmetricslog#Tcpout_Connection...

My tcpout_connection entry looks like this:

name=default-autolb-group:10.10.31.83:9997:0

because the default-autolb-group only contains one indexer.....will add another and confirm

In your example do the numbers match the amount of unique indexers?

- MattyMo
0 Karma

HiroshiSatoh
Champion

Hi, mmodestino
I thought so, but there are obviously more numbers than pipeline number.

0 Karma

mattymo
Splunk Employee
Splunk Employee

what do you mean?
do you not have parallelization turned on?

- MattyMo
0 Karma

mattymo
Splunk Employee
Splunk Employee

ah I see what you mean...updating answer

- MattyMo
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...