...etch such events it is better that we use one syslog server and install UF to monitor and send events written in syslog server. However I saw their is an add-on named as "Splunk add-on for Netscaler C...
...esource on all Splunk Cluster VMs: 12Core CPU(2.4Ghz) 20GB of Ram and SSD in all splunk VMs note (i dont use any event filtering or special process on datain HF in yet , just datagetin and forward...
Below is my use-case (Heavy Forwarders -> Indexers). Need expert assessment.
1) I have very huge log files.
2) So, I have used heavy forwardersto cut down data at source using REGEX t...
Hello,
I have a setup that consists of a Search Head and 2 indexers in a cluster. I also use a self signed SSL certificate between the indexers and my universal forwarders.
For some reason, m...
...erver
Everything works find except that ALL the data that gets forwarded as syslog ALSO gets indexed and there seems to be no way to avoid this. There is no way to filter the incoming data stream an r...
...ctually use the inputs.conf on the TA we built for UFs, that tells those UFs to clone their data for the heavy forwarder, to start monitoring IIS logs (in other words, not changing anything on the HF), i...
one of our end-user clients have massive information stored in ELK stack. Our company needs to collect those datainto Splunk using Splunk Universal forwarder . They can't send us fluentd due to f...
A client is interested in the best ways to generally getdatainto Splunk without installing forwarder on all their machines. Is there a doc on this somewhere?
I can start with:
Decide touse...
...ork. I'm not receiving any events and I've checked in the actual file I'm forwarding - there's datain there.
Basically all events for sourcetype=csi_pclog need to be dropped, except events with t...
...ame to know this uses some polling mechanism as against to UFs which push the data. I've worked with UFs only in the past. Network traffic or intermediate forwarder as a bottleneck,Could these be a r...