...now how I could accomplish this? Your help is much appreciated.
Note: our Splunk instance has a heavy forwarder (where the file is) that is set to send data to our 2 indexers up in the AWS cloud. T...
...hen trying to activate in distributed mode : "Do not configure the DMC in distributed mode if this is a production searchhead. Doing so can change the behavior of all searches on this instance. This i...
Hello, We are in indexer cluster,2indexer,1clustermaster,deployment server & License master,2 HEC and 1 searchhead. I have created tokens in one of my HEC instance and i can able to see logs a...
Hi All,
Currently I have a single instance which acts as indexers as well as searchhead. But i am planning to include another instance and make it as indexers and use the existing machine as search...
When using a stand alone searchhead, we made configuration changes in etc/system/local/ e.g. outputs.conf, limits.conf, etc
I've converted this standalone instance to a searchhead cluster, b...
I have a Splunk Enterprise instance with a 1GB license setup to aggregate logs in a small Windows AD environment (Server 2016 DC, CentOS file server, and < 10 Win10 workstations). I currently h...
I am migrating from a stand-alone Splunk instance to a Splunk cluster (w/ search-head-cluster + indexer-cluster) and I am hitting this problem.
On my searchheads, I have these settings
/opt/s...
I have the following setup with Indexer Discovery + Indexer Cluster + SearchHead Cluster: - Deployment Server - 3 X Indexer + Cluster Manager (Indexer Cluster) - SearchHead Deployer + SearchHead...
...nstalled on both SH, it works locally on both, but my KV store instance seems locally even though I have set 'replicate = true' in my Collection stanza and 'replication_host = FQDN' in server.conf.
R...
...Cluster(s)" column in the MC Setup never shows the label. As such, I get the warning that "This instance is a searchhead deployer without a searchhead cluster label. We recommend you edit this instance...