What is the difference between Cluster master and License master in a distributed Environment?
Any major differences and detailed explanation of both would be great.
...bandoning theindex_master for distributing theindexes.conf file and managing by myself the hand copy/edit ofthe various index files and rolling-restart oftheindexers?
Thanks,
Hi to everyone
I have a design, with four Splunk instances (two search head, and two indexers). I want an "indexercluster" (for replication and fault tolerance), and a "search head cluster" (f...
My current Splunk setup is a clusterof 3 indexers, one in each region. One Master, two Peers. With distributed search enabled between them. My next goal is to create High Availability Splunk e...
What's the recommended best practice to architect a Windows universal forwarder to an indexercluster? Is it better to forward all the Windows UF data to a VIP or just have them go straight to theindexers?
Hello everyone. Currently I have a clusterarchitectureof Splunk Enterprise 8.0.7. SH cluster + IndexerCluster + Master Node + Deployer, all ofthem in Windows. Now I have to d...
...ould anyone please provide us the procedure based on our environment. https://docs.splunk.com/Documentation/Splunk/8.1.1/Installation/MigrateaSplunkinstance Architecture(Linux) :- Server1 - Cluster...
...reate a kind of Distributed Search to get 2 separate data/search-result from first and second instances.
Which architecture and configuration is the best to collect data from mix ofarchitectures?
D...
Hi Splunkers, We have servers running on 2 different on premises Data Centre. We are planning Splunk deployment architecture to fetch the events from server. We are planning to have 1 indexer at e...
Hello!
We need to implement architecture ES Splunk to 400 GB in clustering (SH, IDX). How we should to count numbers of idx for this capacity? In Splunk docs recommend to use per indexer up to 1...