hi experts
trying to deploya HF and forward logs to 2 different indexers. clone data i have 2 UFs feeding windows and syslog logs respectively to a HF.
This is my HF output conf, i think t...
Hello,
I am currently doing a Splunk implementation where I have multiple Universal Forwarders which will be sending information to my HeavyForwarders, where we will be doing a lot of f...
...hat the v 6.0 forwarders are incompatible with so I need to install Splunk version 3.14 onto the box. I see in the documentation that I can make the full installation aheavyforwarder to push to my r...
Hi all, new to splunk, we are regularly burning down our heavyforwarders and as such the IPs change regularly. I need a way to keep the UFs pointed at the HFs but ive read that using an AWS ELB i...
Hi.
I have an Indexer/SearchHead/Deploy server sitting on one zone, and aHeavyForwarder/Deploy server sitting on another zone. Currently my license installed on the Indexer. Since the HeavyForwarder...
...would need a new HeavyForwarder per 200GB per 24 hours?
http://docs.splunk.com/Documentation/Splunk/6.1.3/Deploy/Summaryofperformancerecommendations
Is it advisable to deployheavyforwarders to all clients vs universal forwarders? We have an interest in cutting down on the amount of data indexed and being transmitted across our network. S...
How can I troubleshoot the deployment server or universal or heavyforwarder?
I set up deployment server then in forwarders I run ./splunk set deploy-poll ip:port
But Forwarder M...
...ake other server types (clustered indexers, heavyforwarders, etc.) do this?
I'm hoping to continue to use the deployer/deployment server/etc. commands to deploy configuration changes, but I w...
I'd like to deploya light-forwarder to reduce footprint, but I need to send different inputs to a different index on the indexer.
i.e. OS logs, to osindex, DB logs to dbindex, Application logs t...