...olume I am expecting to process I would be following a Splunk 'Small Enterprise' deployment.
The first bit I am unclear on is around forwarding from this cluster. If I wanted the Indexing cluster i...
...ntermediate forwarder(Universal forwarder itself). Now I need to route data from Intermediate Forwarder in this way: if hostname=x ( IndexerCluster AND Other SplunkEnterprise Instance)&n...
I need details about what to check before I upgrade so I know if my deployment is ready to upgrade. What do I monitor, and how do I benchmark system health before the upgrade?
Hi,
I have installed SplunkEnterprise version locally and configured the below from Splunk Web.
1-forwarding host:port, (localhost:9997)
2-receiving port to match with the same port.(9...
I need details about what to validate after the upgrade so I know it was successful. How can I tell that everything got upgraded correctly, and that the system is healthy and ready to go?
...roperly. However, I then configured my SPLUNK Heavy Forwarder via "Forwarding and Receiving" to send to my clustered indexers (I added indexer1:9997, indexer2:9997) and I am no longer getting the e...
I have a Splunkclustered environment built, both indexer and search head clustering. I would like to know how to make all internal Splunk logs go to the clustered indexers. Thanks!
...ia my SearchHead.
So I installed the CEF (Common Event Format) Extraction Add-on for SplunkEnterpriseto correctly parse these logs. But while all the posts about properly configuring this addon t...
...edundancy and Disaster Recovery purposes.
My questions:
1. Is it possible toforward all raw logs from all indexers to a 3rd party SIEM directly without a Heavy Forwarder?
2. Do I need to change p...
I'm using SplunkEnterprise 8.2.4 and trying to get my forwarders toforward perfmon counters (CPU, Disk Space etc.) into a metrics index at my indexercluster. It seems to me from reading h...