...arget=172.31.25.77:9998. Not rolling hot buckets on further errors to this target messages) by tailing the splunkd.logs on both an indexer and a search-head cluster. On a search-head cluster member a...
I am not sure which Splunk ES related apps go where.
My deployment looks like the following:
Splunk universal forwarder (windows/linux/) + syslog ===> 2 Heavy Forwarders =====> 2 Indexer...
I have a Splunkindexercluster (2 indexers, 1 master node), 1 search head, and multiple forwarders. Is there a way toconfigure source types, input ports, etc from a central web interface, or does e...
...I'm trying to understand, for Add-Ons such as Salesforce, how I ensure data is forwarded to an IndexCluster. I know on a Universal Forwarder that I can setup Indexer Discovery, and I have this w...
I did have a previous post - "How to get search head cluster members toforward internal data toindexercluster? - but don't think it is working correctly - yet.
I am a bit confused by one item i...
I am trying to install a newer version of Splunkenterprise. As part of this, I want the universal forwarders toforward data to both new and old Splunkenterprise - Indexer masters.
Is there a w...
I have multiple XIO clusters and each has a unique hostname. Can I configure the EMC XtremIO Add-on for SplunkEnterprise with multiple hostnames on a single forwarder, or do I need toconfigure s...
I'm running 6.6.2 in multi-site clustered configuration. Read This First tells me:
SplunkEnterprise supports the following upgrade paths to version 7.1 of the software: From version 6.5 or l...
I'm seeing the error below under messages in my Splunkenterprise console:
Missing or malformed messages.conf stanza for TCPOUT:FORWARDING_BLOCKED_Indexer IP ADDress_default-autolb-group DC-Host N...