I am running Splunk Enterprise 8.0.6 and have HadoopData Roll configured, using Hadoop 3.2.1 with Java 1.8.0_282-b08. I have a virtual index configured toarchive an indexto AWS S3. The HadoopData...
...oldToFrozenscript.py
This will archive datato a particular directory that we mention in indexes.conf.
However it faces problems in cases of clustered architecture due to same multiple buckets being c...
We are getting a bunch of the following errors as our AWS EC2 indexers try toarchive buckets to S3 with HadoopData Roll.
How can we fix them or will they get retried and we can ignore them, if s...
Recently I have archived buckets of _internal index(older than 90 days) from one site of splunk indexers toHadoop cluster using https://docs.splunk.com/Documentation/Splunk/8.0.3/Indexer/Archiv...
...n our main searchindexer. We have read through the Splunk documentation, and believe that we will want to use coldToFrozenDir to set up the path.
We are thinking about archiving the datato either A...
While running a query via EMR on a bucket archivedto s3 with hadoopdata roll, I got the following error:
[hadoop] [ip-192-168-4-184] Streamed search execute failed because: Error reading c...
...Roll?
I believe Hadoop Connect exports search results and HadoopData Roll send the raw data journal.gz
Can I use Hadoop Techniques like Hive, Pig..etc for analytics on the archiveddata sent to...
...nalytics-for-hadoop-on-amazon-web-services-elastic-map-reduce.html. I have the provider up and working and can search HDFS data directly on the EMR node but run into issues when trying to configure a v...
I'm working on pushing out Hadoopdata roll for archiveddatato our index cluster. The buckets are rolling as expected and I have buckets in hadoop but I'm not able tosearch the archivedindexes i...
...ilesystem. This looks something to deal with Hadoop+S3 , which Im not quite aware of. I'm very new to AWS. I thought Splunk can send data directly to S3 for archival. Isnt that possible?
The d...