I currently have two instances of splunk running on two separate hosts. I recently purchased a license so that I can consolidate the two onto one host. Is there a way to consolidate indexed logs/data...
...nd inputs.conf.dist,index and role and we built it that way since now we are consolidating all the apps in a cluster to utilize same index and roles but have different hosts/inputs .
Question - H...
Hello,
I googled around for similar questions but could not find anything, so I'm sorry if this question has already been asked before. If i want to index large amounts of data using multiple f...
...y My Splunk Enterprise. On my forwarder, I configured it to monitor the /var/log/audit/audit.log so my indexer would receive that data. So now I am wondering why TA_linux-auditd is installed with a i...
Hello,
Am trying to extract UNIX CPU data core wise for multiplehosts, Am using the below query for extract,
source=cpu host="XYZ"
| multikv fields CPU pctIdle
| eval Percent_CPU_Load = 1...
...plunk dashboard to show me either Production or DR input data based on drop down list at the top of dashboard. How do I carry out this without duplicating data coming from both the hosts i.e PROD and DR....
This question is slightly theoretical so kindly bear with me. I am trying to make a timechart for multiplehosts on a single graph. The event sampling is every 15 mins and I have to consider the data...
Hi
I want to track space usage of directories on multiplehosts eg:- /var/tmp so that I can check which directory/subdirectory is growing in space, any new directory created etc.. can you please s...
I have a clustered application running in active/passive configuration. We run a report at the beginning of every month that gathers a whole bunch of stats from the file system and other places. T...