All Splunk Apps are installed on Linux Servers and we will apply OS patch. And i have 3 Indexers, 4 Search Heads, 1 Deployment Server and 1 Heavy Forwarder (an Indexer Cluster is integrates w...
One of th requirement of Multisite indexer cluster with SmartStore is Site locations host two object stores in an active-active replicated relationship. Depending on the deployment type, t...
Hi, I've a scenario where our organisation is supposed to only send logs from servers to clients indexers. We have decided to use UF and deployment server. We need to know what are known d...
Hello,
I'm trying to capture Active Directory information from an AD server. I installed an universal forwarder in this server, and using deployment server I configured an input.conf as the m...
Hello All, We have a single instance Splunk enterprise (version 7.1) deployment on Linux which is doing everything . We would like to monitor our AD using SPLUNK. I am confused by reading http://d...
...s deployment client
* Added firewall rule to allow destination port 9997
* checked using "splunk list forward-server" to confirm server is listed in "active" section
On Splunk OVA enterprise s...
Anyone know the best way to monitor deploymentactivity of a splunk server? I've found DeploymentMetrics coming from the deployment serer, and I see DeploymentClient and DeployedApplication m...
We are planning to build an ACTIVE-ACTIVE multisite Splunk deployment, wherein each data center will have its own cluster master along with a set of search peers and search heads.
We are c...
Newly upgraded Splunk to 8.1.5 from 7.3.x and seeing the below error message on DMC Search Activity:Instance
Multiple renames to field 'Type' detected. Only the last one will appear, and p...
Sorry if my questions sounds silly but this is my first Splunk deployment plus I am not even familiar working with AD and Exchange.
I had to configure Splunk to collect Active Directory and M...