...s a cluster setting that is removing it. What am I missing? We only have to get these remaining indexes off so we can decommission this indexer. Let me know if you need more clarification on the issue....
Hi all, can anyone confirm the behaviour? when running: | rest /services/data/indexes | table title *datatype*
I'm only getting back event indexes. From the documentation : https://docs.splunk...
Hi! I have a setup where I must clone and forward data to a third party. Can somebody clarify if I disable useACK that even though a destination is unreachable that the flow to other outputs does n...
Greetings!!
1.a. I need to check data size indexed in indexers per day, per month and per year in GB?
1.b. whatif the dataingested per day is 200GB/day, How do I calculate to know t...
I've struggled on this issue for the past few days and Ican see to resolve it.
I've checked and rechecked my config.
None of my data gets indexed when my application is copied (with os path m...
...ots of CPU free. 1st - How to I monitor the history of the data coming in from the HF->indexers 2nd - Can you share some settings for the heavy forwarder and the indexers please to get the data...
...is the difference (aside from not removing a CR/LF)? What did I do wrong in the first one to cause Splunk to not actually prevent the data from being indexed? These are both in the etc/system/l...
...onnection_host = ip
disabled = 0
I would like to find whatdatais coming in on these ports, set them all up to come in on 9997, and send them to their own index, so that Ican allow the managers of that data...
The question pretty much sums it up.
I am wanting to get PerfMon datainto a Metrics index and have been banging my head against it for about a week now. So far, I have been unsuccessful in my e...
Hello, I am using Splunk Enterprise 7.3.2. and I have structured event data within an events index that I am trying to convert into metrics data so that Ican store it in a metrics index. I a...