is there a possiblity to combine a hunk (virtual) indexand a normal splunk index (for example a summary index) in one search? when a try it naiv with
index="virtualindex" index="s...
Does this seem like a good setup for a dedicated Search head, indexer for avirtualized Splunk?
Search Head
- 8 core 16 GB Ram
Indexer
- 8 core 8 GB Ram 1 TB Hard Drive
We will h...
In regular Splunk I can easily search for
index=index1 OR index=index2 <search term> | stats count by index
Then I get results from either index.
When I setup avirtualindex in H...
Hi,
I have 2 virtualindexes, both return data, and both return for a specific search.
But if I try and join and get no results, and if I try an 'or' I get no results.
index=filea ID=2...
...DFS with read/write permissions and use this as the target of asearch with the collect statement such as index=syslog date_hour=12 | collect index=collect_test , no data is written to the virtualindex...
In Hunk, where is the documentation for verbose mode vs smart mode for virtualindexes (VIX)s??
Afaict, verbose mode just "drops down to" HDFS and doesn't invoke a MapReduce Job.
Whereas as l...
Hello people,
Is there a way I can hard-code a drop-down search to display all virtual machines in my network on the drop-down? Without getting the duplicating errors all the time :
Sample of m...
...niversal forwarders pushing data to an indexer / search server. If I wanted to consider high availability options within a single site, I might want to cluster the indexers, but as I only have two s...
We just upgraded Splunk IT Service Intelligence from 2.2.0 to 2.4.1 and want to add in pre-built KPIs for VMWare. Our VMWare is collecting the data - the verification search is populated ( index=v...
Hi
Our data is stored in the following directories. Each directory contains 1 day of data.
s3n://rcs-cms-event/cep/prod/consolidated/appAnalytics/event_date=2015-10-27/
We set up our virtual...