...Roll archiving process to S3 works, and the archived index is created in S3. However, when I try to search that archived index located in S3, I get the error below (which is from search.log). Has a...
I have an indexer cluster with a replication factor of 3. If I were to implement HadoopDataRoll, would only one copy of each event be archived to Hadoop at freeze time, or would all three bucket c...
...opied as per below doc.
https://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/Automatearchiving
Im planning to use HadoopDataRoll to send the splunk index data to Hadoop for longer R...
Hi,
I'm searching for the documentation for the new 6.5 hadoopdataroll feature, and unable to find it. Can someone point me to it? Or where it's setup within Splunk? Nothing obvious stands o...
Documentation says Archive indexer data to meet your data retention policies without using valuable indexer space.
How exactly does this help Splunk indexers? Does Hadoop has more compression r...
We are getting a bunch of the following errors as our AWS EC2 indexers try to archive buckets to S3 with HadoopDataRoll.
How can we fix them or will they get retried and we can ignore them, if s...
We use the Splunk HadoopDataRoll to move our frozen data over to our Hadoop cluster. The writing of the data to HDFS seems to work pretty well, but the searching of it through Splunk d...
...nformation on how this works is spread everywhere and one might think you require a Hadoop cluster here but some information seems to point to the fact that one can just have a Hadoop client on Splunk t...
I am trying to configure HadoopDataRoll to archive data to a S3-compatible data store.
I can confirm that I can access the data store via s3cmd (https://s3tools.org/usage) as well as Hadoop o...
How can I send splunk cold buckets to S3?
We have our on-premises splunk and send Splunk data to S3 for longer storage.
I came across this HadoopDataRoll that sends the splunk data to S3A f...