The purpose of this topic is to create a home for legacy diagrams on how indexing works inSplunk, created by the legendary Splunk Support Engineer, Masa! Keep in mind theinformation and diagrams in...
...problem with thefiltering
I thought that you define a default group for events and messages where you don't have routing rules, so that everything that doesn't have a stanza in props.conf and t...
I can never remember where I need to configure my various Splunk settings. Some need to be on the forwarder side, some on theindexers and I even sometimes need them on the search head...
So w...
...eneric_sourcetype andthen processes the transfomrs for the sourcetype filtering but then sends the events directly instead of "re-parse" them with the given settings for the new sourcetype.
Is t...
I have app datarouting from one set of Relay Forwarders (DEV) into another set of Relay Forwarders (sandbox) andthen on to a set of indexers. I need to route thedata to a specific index if the f...
From indexerA I am trying to forward Windows Event Logs and IIS Logs to indexerB. The Windows Event Logs are being forwarded properly, but the IIS Logs (sourcetype=iis) are not.
(Splunk E...
I'm seeing the error below under messages in my Splunk enterprise console:
Missing or malformed messages.conf stanza for TCPOUT:FORWARDING_BLOCKED_Indexer IP ADDress_default-autolb-group DC-Host N...
Good Morning,
I'm trialing Splunk Cloud in anticipation of a purchase. I have installed Splunk Enterprise as the deployment server and universal forwarders on three servers. My clients are s...
...INFO dispatchRunner - registering search time components of build time module name=vix
09-25-2018 06:17:18.357 INFO dispatchRunner - Getting search configuration data from: /opt/splunk/etc/m...