We are currently using a Splunk Enterprise environment with one search head and one indexer. We enabled datamodelacceleration because the performance of the search became poor as we used the s...
...ame_10
5/22/2020, 2:00:52 PM.
The blocked host name belongs to a domain controller where I just deployed a UF. I'm not receiving any data from this forwarder.
This is harder than I a...
Problem:
Excessive disk space consumed on indexer in $SPLUNK_HOME/var/run/searchpeers to the point where the indexer runs out of disk space. It appears that the bundle files are not being reaped.
Also, what actually does Splunk do when we give the below line in datamodels.conf file?
acceleration.max_concurrent = 1
could someone provide me a basic level understanding of datamodels.conf?
...plunk'), but does not reference that volume. Space used by coldPath will not be volume-mananged. Please check indexes.conf for configuration errors.
09-25-2018 06:17:18.388 WARN IndexConfig - idx=u...
...alues from the lookup in it's version when I started the acceleration (or restartet Splunk) or do the updates of the lookup reflect in the accelerated datamodel? If they do reflect then which delay c...
Hi,
I'm using 6.1.x and have built a datamodel with a dynamic lookup attribute inside. I wonder if I enable the acceleration on this datamodel, how the dynamic lookup attribute pick up the v...
Hi Base,
what is the impact when the content of $Splunkhome$/var/run/searchpeers will be deleted?
In an installation with 7 Searchhaeds this folder grows and grows and grows...
THX
...s), will change. And in an auto-recover will lose those state changes.
Therefore, I would like to back-up all critical state in a way that is easy to auto-recover.
I have found these reference...