I currently have two instances of splunk running on two separate hosts. I recently purchased a license so that I can consolidate the two onto one host. Is there a way to consolidate indexed logs/data...
Hi All, i need to consolidate / correlate datafrom 2 different indexes as explained below. I have gone thru multiple posts on this forum from experts relevant to this but somehow for my use case, t...
...nd inputs.conf.dist,index and role and we built it that way since now we are consolidating all the apps in a cluster to utilize same index and roles but have different hosts/inputs .
Question - H...
Hello,
I googled around for similar questions but could not find anything, so I'm sorry if this question has already been asked before. If i want to index large amounts of data using multiple f...
...y My Splunk Enterprise. On my forwarder, I configured it to monitor the /var/log/audit/audit.log so my indexer would receive that data. So now I am wondering why TA_linux-auditd is installed with a i...
Hello,
Am trying to extract UNIX CPU data core wise for multiplehosts, Am using the below query for extract,
source=cpu host="XYZ"
| multikv fields CPU pctIdle
| eval Percent_CPU_Load = 1...
Hi
I want to track space usage of directories on multiplehosts eg:- /var/tmp so that I can check which directory/subdirectory is growing in space, any new directory created etc.. can you please s...
This question is slightly theoretical so kindly bear with me. I am trying to make a timechart for multiplehosts on a single graph. The event sampling is every 15 mins and I have to consider the data...
...plunk dashboard to show me either Production or DR input data based on drop down list at the top of dashboard. How do I carry out this without duplicating data coming from both the hosts i.e PROD and DR....