I am running Splunk Enterprise 8.0.6 and have HadoopData Roll configured, using Hadoop 3.2.1 with Java 1.8.0_282-b08. I have a virtual index configured toarchive an indexto AWS S3. The HadoopData...
...oldToFrozenscript.py
This will archive datato a particular directory that we mention in indexes.conf.
However it faces problems in cases of clustered architecture due to same multiple buckets being c...
We are getting a bunch of the following errors as our AWS EC2 indexers try toarchive buckets to S3 with HadoopData Roll.
How can we fix them or will they get retried and we can ignore them, if s...
Recently I have archived buckets of _internal index(older than 90 days) from one site of splunk indexers toHadoop cluster using https://docs.splunk.com/Documentation/Splunk/8.0.3/Indexer/Archiv...
While running a query via EMR on a bucket archivedto s3 with hadoopdata roll, I got the following error:
[hadoop] [ip-192-168-4-184] Streamed search execute failed because: Error reading c...
...ilesystem. This looks something to deal with Hadoop+S3 , which Im not quite aware of. I'm very new to AWS. I thought Splunk can send data directly to S3 for archival. Isnt that possible?
The d...
I'm working on pushing out Hadoopdata roll for archiveddatato our index cluster. The buckets are rolling as expected and I have buckets in hadoop but I'm not able tosearch the archivedindexes i...
Hi,
I'm searching for the documentation for the new 6.5 hadoopdata roll feature, and unable to find it. Can someone point me to it? Or where it's setup within Splunk? Nothing obvious stands o...
...ehind this method is that if for any reason I ever needed to restore the archiveddata for searching I could simply setup a new Splunk indexer, attach the archived EBS volume, and point a search h...
...he next file is written from 8 AM to 7 PM. But this file is not indexed until around 7 PM.
We are on a Universal forwarder 7.0.3
Below is the monitoring stanza
[monitor:///opt/mapr/hadoop/hadoop...