...erm. Warm/Cold/Frozen will be something like 6 months/1.5 year/5year.
But, I don't want to be completely dependent on synchronization of my indexes between the 2 sites, and data corruption/loss w...
In some cases, the Splunk Phantom virtual appliance can lose its timesynchronization with the systemtime. For example, some virtual machine management functions can be run that would revert the S...
...esting on (I have not yet enabled forwarding, it's running as a standalone demo.)
TimeSynchronization:
All Unix systems are synced via NTP; and the windows hosts are either synced via NTP directly, o...
Good Morning,
I'm trialing Splunk Cloud in anticipation of a purchase. I have installed Splunk Enterprise as the deployment server and universal forwarders on three servers. My clients are showing ...
Hello please I will ask several questions and thank you for taking step by step because I am a student and this is my first time using splunk enterprise: I want to monitor my active directory I f...
we have 3 deployment servers (DS1,DS2,DS3) in our splunk instance. DS2 and DS3 are deployment clients of the deployment server on DS1 to provide for synchronization of deployment-apps.
From a f...
...omains. Basically, I want to end up with an $SPLUNK_HOME/etc/system/local/inputs.conf that dynamically assigns the host name and index values based on which desktop it is running on. Something that l...
When setting up my Splunk deployment, I was asked about what timezone I want the servers to have. I just assumed I should use my local time zone for convenience. Am I being short sighted?