Hello
I have 5 indexers managed by Cluster Master.
On the indexes.conf (located as master-app) I have the following configuration:
[default]
maxTotalDataSizeMB = 1000000
f...
Hi, I understand that importing the evtx format into Splunk consumes more licenses than the volume displayed. (Because evtx is a compressed format.)
Am I right in thinking that I will consume a...
Hi
I am currently using the free license as we are investigating the product for possible furture use in our system. One thing I have noticed is I am getting a Daily Indexingvolume limit e...
Hi!
Since upgrading to v.4.2 we have been having problems with going over our daily indexingvolume limits. I have tried following the guidance here to try and identify the cause, but am having p...
It seems like our indexers do not properly get distributed load in our cluster according to our volume report alerts, it seems rather unbalanced and varies per day.
One example:
> splunk1-d...
Hi Splunkers,
I want to create an Instance overview dashboard, and one KPI should be today's estimated indexingvolume. The daily traffic varies greatly by time (significantly more over the w...
Hi,
I am currently testing out two searches to report and alert on the daily indexed volume.
The first search is as follows.:
index=_internal sourcetype=splunkd LicenseManager-Audit t...
...ption 1 Can I then define a volume in /etc/system/local/indexes.conf on every indexer. On idx01: [volume:coldvolume] path = /mnt/coldvolume/idx01/ On idx02 [volume:coldvolume] path = /m...
Hello friends!
Today there are very strange behavior on splunk server.
On the average Volume used today = 50-120MB
But today i has some crazy numbers = 2,936 MB, but number of events in the d...