Hello,
I'm looking to set up our search head to send summary index data it generates back to our indexers in a distributed environment.
I found the following question, and I understand the t...
In our enterprise, there is already another team which has setup Splunk Search Heads andIndexers in their own AWS account (say A). We are planning to indexand store new data in our AWS account (s...
Say I have two indexers in two different datacenters, and I want to distributesearches across the WAN/VPN/Internet between them. What kind of bandwidth is necessary for optimal search performance? F...
...alue combinations and 10's of millions of dups, across a few dozen indexers. The results distribution is likely to be neither sparse nor dense, but long-tail - a few combinations will predominate, w...
I have a single indexer and single search head with the indexer attached as a search peer and I created one index called "winevent" on the indexer.
I don't understand why the search head cannot s...
Hi all,
My old, primary Splunk indexer/search head is being retired (v4.1.4). In its place is 4 new indexing servers that are carrying the indexing load for me (all running v4.1.5). Each of t...
Hi,
In a distributed mode with 1 search head and 4 indexers, when making a search through the search head, 2 of the for 4 indexers are not showing indexed data except internal logs of other S...
I have a single instance splunk (splunk A). now I want to do distributed search contain 1 indexer (splunk A)+ 1 search header (splunk B) and use the existing Splunk enterprise (splunk A) as the index...
It looks like indexes on both nodes are updated with the same entries. Does distributed indexing load andindex the same data from a source to both indexers?
UPDATE
It turns out that I've c...
Hi According to the document here, cluster master distributes an app under indexer clustering environment. https://docs.splunk.com/Documentation/Splunk/8.1.3/Indexer/Manageappdeployment I...