...oints and the results are truncated. I have played with charting.chart.resultTruncationLimit but that only gets so far.
Note: the span of 5m cannot be changed or the datais skewed.
Is there a w...
Hi Splunkers, I have a problem with a Per-Event Index Routing use case. In involved environment, there are some data currently collected in a index named ot. Here we have some logs that must be s...
Hello,
We are still facing the following issue when we put in maintenance mode our Indexer Cluster and we stop one Indexer.
Basically all the Indexers stop ingesting data, increasing their q...
Greetings!!
1.a. I need to check data size indexed in indexers per day, per month and per year in GB?
1.b. whatif the dataingested per day is 200GB/day, How do I calculate to know t...
Hi all, can anyone confirm the behaviour? when running: | rest /services/data/indexes | table title *datatype*
I'm only getting back event indexes. From the documentation : https://docs.splunk...
I guess my real question is how do I move Splunk from one company to another, including some but not all of the data and the indexes for the selected data? I see Ican copy config and indexes from t...
...s a cluster setting that is removing it. What am I missing? We only have to get these remaining indexes off so we can decommission this indexer. Let me know if you need more clarification on the issue....
The question pretty much sums it up.
I am wanting to get PerfMon datainto a Metrics index and have been banging my head against it for about a week now. So far, I have been unsuccessful in my e...
Hello, I am using Splunk Enterprise 7.3.2. and I have structured event data within an events index that I am trying to convert into metrics data so that Ican store it in a metrics index. I a...
Hi! I have a setup where I must clone and forward data to a third party. Can somebody clarify if I disable useACK that even though a destination is unreachable that the flow to other outputs does n...