I am running Splunk Enterprise 8.0.6 and have HadoopDataRoll configured, using Hadoop 3.2.1 with Java 1.8.0_282-b08. I have a virtual index configured to archive an index to AWS S3. The HadoopData...
I have an indexer cluster with a replication factor of 3. If I were to implement HadoopDataRoll, would only one copy of each event be archived to Hadoop at freeze time, or would all three bucket c...
...opied as per below doc.
https://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/Automatearchiving
Im planning to use HadoopDataRoll to send the splunk index data to Hadoop for longer R...
...Roll?
I believe Hadoop Connect exports search results and HadoopDataRoll send the raw data journal.gz
Can I use Hadoop Techniques like Hive, Pig..etc for analytics on the archived data sent t...
Hi,
I'm searching for the documentation for the new 6.5 hadoopdataroll feature, and unable to find it. Can someone point me to it? Or where it's setup within Splunk? Nothing obvious stands o...
Documentation says Archive indexer data to meet your data retention policies without using valuable indexer space.
How exactly does this help Splunk indexers? Does Hadoop has more compression r...
We currently have our Splunk environment running on Server 2012. I've built out an Hadoop cluster in *NIX and currently building a *NIX box for Hadoop Analytics. Will I be able to rolldata from o...
We are getting a bunch of the following errors as our AWS EC2 indexers try to archive buckets to S3 with HadoopDataRoll.
How can we fix them or will they get retried and we can ignore them, if s...
Looking at new 6.5 Hadoopdataroll feature - will the bucket reader be able to read this data? Also, would it be possible to export the "raw data", but keep the tstats?