...imit exceeded today" today. What will Splunk do tomorrow? Simply go on indexing since the next day has begun or will all data which wasn't indexed today be lost?
Thank you very much. Kind regards,
Katsche
In 4.2 when a search was executed just above the results there were three small graphics (next to the paginator) which allowed you to toggle the view (Events List, Events Table, and Results Table)....
...an notifications=1, actions=1, managedSearchCount=0
It used to be that I could see my scheduled search runs in splunkd.log like above. This was very useful for debugging. Whathappened to them?
I installed 4.1.1 this morning and have been unable to complete the installation or start Splunk. What kind of nastiness could occur if I ran the 4.1 installer in the hope of getting Splunk r...
Hello,
Having a distributed environment with N indexers and M servers sending data in a load-balanced way (autoLB=true) towards those indexers, whathappens if the minimum free space is reached f...
...ries to forward data to a specific indexer and if it is down, does UF re-try sending the SAME data to the next indexer available in the auto-load balancing list?
PS: I referred this document already a...
I have a Universal Forwarder reading data in a Tab Separated format. I want to apply the INDEXED_EXTRACTIONS = TSV to it.
Do I need to put that on the Indexer or the Forwarder?
A further qu...
Hi,
Since I cannot find a way to test this with a large amount of data, I was wondering what will happen if I want to blacklist text files in a folder, but whitelist text files in a subfolder? E...