We are currently using a Splunk Enterprise environment with one searchhead and one indexer. We enabled data model acceleration because the performance of thesearch became poor as we used the s...
For KVstore, $Splunk_HOME/etc/system/local/sever.conf was configured to use SSL. However, the following error is occurring and the kvstore process is not starting properly. Regarding the Web UI, w...
Hi,
Could you please help me to create a search which can list all apps enabled in Splunk (on splunk searchhead) and their respective version number? We have multiple Searchheads and there is s...
...ecomissioned soon as well
So i need to enable splunkweb on one of our DR indexers so it can act as a SH and continue indexing.
I am not too worried about performance as search will just be needed on the...
I would like to enable to search assistant on my SearchHead Cluster. The documentation recommends an edit to the file user-prefs.conf.spec.in. (Is this a bad idea?)
Described here:
https://d...
I am planning to created deployment enviorment in splunk. And will use these phases in time
1) one searchhead and one indexer in deployment enviorment
2) one serach heads and two indexers in d...
...tandalone server to searchthe data ingested to distributed/clustered environment?
I just want to enablethesearch in standalone server, and I don't want to have the data inside standalone server, a...
Hi, we have deployed a searchhead cluster with two searchhead and one deployer. when we run : /opt/splunk/bin/splunk apply shcluster-bundle -target https://sh1.example.com:8089 we get the...
Hello, I have an automated upgrade plan that does the following: Puts the cluster in maintenance mode splunk enable maintenance-mode Goes 1 by 1 on each of the 3 indexer peers and runs: s...