...eason I ask: it does not exist in my instance on the Deployment Server (only apps.conf in that folder); I am trying to figure out what it should be and how to fix what seems to be a broken "Splunk Add-o...
Does anyone have any good resources about indexes and index management?
Before I set up a bunch of indexes, I'd like to know more about the how indexes impact my deployment.
...earch Head. I am able to successfully grant Splunk access to my Box account and pull events.
But I cannot add the Data Inputs, as specified in the configuration instructions. In fact, when I try to...
What is a good procure to follow for installing a Splunk Universal Forwarder on a Linux host for the first time? A step by step process might help first time users get data into Splunk and u...
I have a custom index defined in apps/search/local/indexes.conf that receives data pretty much continuously.
In migrating from a singleinstancedeploymentto a clustered indexer with s...
In this case I'm using the Dell EMC VMAX Add-on for Splunk (TA_Dell_VMAX) to monitor an array. It only allows for one IP to be specified, and we have an additional VMAX array that needs to be m...
Hi, I have a CloudTrail data source feeding into the AWS Add-On app on a single-instance Splunk deployment. If I go to the AWS app and do a search from within that app, Splunk is able to e...
...nformation on how to configure a Splunk forwarder or single-instanceto receive a syslog input, see "Get data from TCP and UDP ports" in the Getting Data In manual.
Which I find incredibly limited and n...
...indexer, and single heavy forwarder. I am setting up the heavy forwarder as some of the splunk apps we want to use require it for "pre parsing". With that in mind, i have the three instances c...
...dev being a single server for development only purposes using log samples and made up data for testing logic on dashboards.
production environment would ideally be a clustered set up c...