I have an indexer cluster with a replication factor of 3. If I were to implement HadoopDataRoll, would only one copy of each event be archived to Hadoop at freeze time, or would all three bucket c...
...opied as per below doc.
https://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/Automatearchiving
Im planning to use HadoopDataRoll to send the splunk index data to Hadoop for longer R...
...Roll?
I believe Hadoop Connect exports search results and HadoopDataRoll send the raw data journal.gz
Can I use Hadoop Techniques like Hive, Pig..etc for analytics on the archived data sent t...
Hi,
I'm searching for the documentation for the new 6.5 hadoopdataroll feature, and unable to find it. Can someone point me to it? Or where it's setup within Splunk? Nothing obvious stands o...
Documentation says Archive indexer data to meet your data retention policies without using valuable indexer space.
How exactly does this help Splunk indexers? Does Hadoop has more compression r...
We currently have our Splunk environment running on Server 2012. I've built out an Hadoop cluster in *NIX and currently building a *NIX box for Hadoop Analytics. Will I be able to rolldata from o...
We are getting a bunch of the following errors as our AWS EC2 indexers try to archive buckets to S3 with HadoopDataRoll.
How can we fix them or will they get retried and we can ignore them, if s...
...Roll archiving process to S3 works, and the archived index is created in S3. However, when I try to search that archived index located in S3, I get the error below (which is from search.log). Has a...
Looking at new 6.5 Hadoopdataroll feature - will the bucket reader be able to read this data? Also, would it be possible to export the "raw data", but keep the tstats?