In my environment, I have two indexers for one Search head.
I think that these commands like "search", "dedup", "transaction" are processed by indexer in distributedsearch.
But are these c...
Hello.
I'm running on RHEL 7 with 6.6.3 and an Indexer cluster (3 peers), and have 2 Search Heads not in a SHC but connected induvidually to the index cluster.
I try to use KV store with a c...
Hi,
There are 2 splunk servers( A and B) that have differente data and indexes. I have setup distributedsearch from A to B and B to A.
searches done from A to B: everything is working as e...
Folks,
I have a Splunk 4.2.4 search-head and indexer on another machine in a distributed setup.
I'm getting an error in my splunkd.log about my knowledge bundle timing out replicating from search...
...ndexers. On the search head: The full message in splunkd.log is: "Global key files are invalid. This server cannot distribute searches to other servers." In Settings » Distributedsearch...
Hello Splunkers,
I was wondering if there is a Splunk documentation or an article about how certain search commands behave in a distributed environment. (i.e. mainly the usage of Join, S...
I am about to upgrade 8.1.3 distributed / clustered environment to 9.0.4. Per Docs> Migrate your App Key Value Store storage engine from the Memory Mapped (MMAP) storage engine to the W...
Hello. I'm a new Splunk user, and I'm quite uncertain about how to index some distributed data. I have one SH and multiple Indexers located around the globe. Each of these Indexers has a local log f...
Hello Splunkers!
I am currently setting up a distributed Splunk system in our company.
It consists of: 2 Indexers and a Cluster Master Node, a standalone Search Head and a standalone Deployer/L...
I have a 3 node search head cluster that backs on to a single indexer (its a test environment). All servers are 6.3.2. For one particular sourcetype, the search time xml field extractions do not f...