What factors should be taken into consideration in deciding the appropriate number of replicationThreads? Are there any performance considerations for increasing this value?
...he ‘distsearch.conf’ on SH (SPLUNK_HOME/etc/system/local/distsearch.conf)
I wonder why the peers where not in the file already, as the others were in it, and I never had to change it before.
I...
....conf stanza, and not sure which one is the right one. Splunk/8.1.2/DistSearch/Configuredistributedsearch - here states: "Add the search peers To connect the search peers: 1. On t...
when configuring a distributed search ... why when i create a new server on the web interface it asks for a username:password though in distsearch.conf there isn't a place for it?
Is there s...
...earch heads, and restarted. In the app is a distsearch.conf file containing the following:
[replicationBlacklist]
winLookup = *windows_perfmon_details.csv
When I check with btool, I can see t...
Hi, We have 3 search head in a cluster and 3 indexers in non clustered environment. Whenever we do a rolling restart of the SH, the distsearch.conf in etc/system/local and some lookup csv in s...
in the distsearch.conf on our search head we can blacklist applications [replicationBlacklist] splunk_app1_blacklist = apps/splunk_app1/... splunk_app2_blacklist = apps/splunk_app2/... W...
We noticed that the 6.3.1 version of the Anomali Threatstream App for Splunk ships with a distsearch.conf file. That conf includes a replication whitelist for all json files (see below). Assuming t...
Does anyone have any examples of regex used in the Blacklist patterns for distsearch.conf? We are trying to limit what gets replicated in distributed searches and I thought this would be a good s...
...eers instead"
After some re-search and looking through answers site, this could be due to inconsistent distsearch.conf on some of the search heads in the cluster ; so I updated and removed all t...