Activity Feed
- Got Karma for Re: cluster configuration bundle files for sourcetype and index addition. 06-05-2020 12:47 AM
- Got Karma for Re: cluster configuration bundle files for sourcetype and index addition. 06-05-2020 12:47 AM
- Got Karma for Re: cluster configuration bundle files for sourcetype and index addition. 06-05-2020 12:47 AM
- Got Karma for Re: Cluster upgrade 5.0.5 to 6.1.2 - Estimate on how long?. 06-05-2020 12:47 AM
- Got Karma for Re: Cluster upgrade 5.0.5 to 6.1.2 - Estimate on how long?. 06-05-2020 12:47 AM
- Got Karma for Re: Why Splunkd daemon not responding after distributing configuration bundle with master node?. 06-05-2020 12:47 AM
- Got Karma for Re: Why Splunkd daemon not responding after distributing configuration bundle with master node?. 06-05-2020 12:47 AM
- Karma Re: Calculating IOPS from bonnie++ results for Ron_Naken. 06-05-2020 12:46 AM
- Karma Re: Calculating IOPS from bonnie++ results for etbe. 06-05-2020 12:46 AM
- Got Karma for Calculating IOPS from bonnie++ results. 06-05-2020 12:46 AM
- Got Karma for Calculating IOPS from bonnie++ results. 06-05-2020 12:46 AM
- Got Karma for Calculating IOPS from bonnie++ results. 06-05-2020 12:46 AM
- Got Karma for Calculating IOPS from bonnie++ results. 06-05-2020 12:46 AM
- Got Karma for Calculating IOPS from bonnie++ results. 06-05-2020 12:46 AM
- Got Karma for Re: PDF Server App with Search Head Pooling. 06-05-2020 12:46 AM
- Got Karma for Re: How to stop a cluster?. 06-05-2020 12:46 AM
- Got Karma for Re: permissions question. 06-05-2020 12:46 AM
- Posted Re: cluster configuration bundle files for sourcetype and index addition on Getting Data In. 07-11-2014 08:23 AM
- Posted Re: Cluster upgrade 5.0.5 to 6.1.2 - Estimate on how long? on Installation. 07-11-2014 08:18 AM
- Posted Re: splunk not parsing txt file from forwarder correctly on Getting Data In. 07-11-2014 08:12 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
5 |
07-11-2014
08:23 AM
3 Karma
As described in Splunk documentation, you should put your stuff in $SPLUNK_HOME/etc/master-apps/app1, $SPLUNK_HOME/etc/master-apps/app2 instead of $SPLUNK_HOME/etc/master-apps/_cluster
Everything about the configuration bundle can be found here :
http://docs.splunk.com/Documentation/Splunk/6.1.2/Indexer/Updatepeerconfigurations
... View more
07-11-2014
08:18 AM
2 Karma
The link shared by Martin is essential to the upgrade. Read it at least twice 🙂
I did an upgrade of a 5.0.7 cluster about two weeks ago. The target was Splunk 6.1.1.
One Search Head, one Master Node, three Peers with about 7 TB each of data.
The upgrade itself took about 15 minutes.
The cluster synchronization afterwards took about 2 hours to get everything searchable and replicated !
... View more
07-11-2014
08:12 AM
You should tell Splunk how an event looks like in order to split the events correctly.
Could you post a sample of your data ?
... View more
07-11-2014
08:07 AM
2 Karma
Hello,
It looks like your Master Node does not "see" any of your peers.
It could be a configuration problem (i.e. secret key not properly shared) or a network problem.
Make sure the [clustering] stanza in the server.conf files on all members of the cluster (master node, search head, peers) are homogeneous.
Relevant stuff can be found on the Splunk Docs site : http://docs.splunk.com/Documentation/Splunk/6.1.2/Indexer/Clusterdeploymentoverview
Also, you should NOT put anything in $SPLUNK_HOME/etc/master-apps/_cluster as it is reserved for splunk stuff.
Instead you should put your apps in $SPLUNK_HOME/etc/master-apps/app1, $SPLUNK_HOME/etc/master-apps/app2 and so on.
Stuff regarding the Configuration bundle :
http://docs.splunk.com/Documentation/Splunk/6.1.2/Indexer/Updatepeerconfigurations
Regards.
... View more
05-27-2014
08:30 AM
1 Karma
Roles are implemented within Splunk with different capabilities : http://docs.splunk.com/Documentation/Splunk/6.1.1/Security/Rolesandcapabilities#List_of_available_capabilities
If the power user you're talking about has the proper capability, (s)he'll be able to change Permissions.
Another possibility is to do that directly by editing the .conf files within the user's directory.
... View more
07-23-2013
03:00 AM
1 Karma
Ok. gfuente has written some nice tips up there, and you can also find the proper order for upgrading Splunk here : http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Upgradeacluster and that will help you a lot regarding your project of patching up the servers themselves.
... View more
07-23-2013
02:43 AM
Well then, it all depends on how your forwarders are configured, what are your rep and search factors, and how the various functions are split across your 2 hosts : master node ? search head ? indexers ?
... View more
07-23-2013
02:29 AM
Have you read this page ?
http://docs.splunk.com/Documentation/Splunk/5.0.3/Indexer/Restartthecluster
Everything standard is explained there.
... View more
02-18-2013
06:35 AM
1 Karma
This app requires the Xvfb (or xvfb) package depending on the Linux distro you are using.
Cheers.
... View more
02-14-2013
09:16 AM
5 Karma
Hello,
I was wondering how to obtain IOPS from bonnie++ results.
The various executions of bonnie++ have been done using a size of twice the RAM, and not the root user.
Here are the results:
# bonnie++ -d /data -s 12g -qfb
1.97,1.97,host28,1,1360870223,12G,,,,434320,86,116822,22,,,116187,9,1362,32,16,,,,,15457,27,+++++,+++,2854,9,32642,45,+++++,+++,1624,6,,212ms,158ms,,178ms,818ms,125ms,1310us,234ms,103ms,53424us,182ms
# bonnie++ -d /data -s 16g -qfb
1.97,1.97,host56,1,1360869078,16G,,,,392047,38,133174,5,,,363574,5,586.2,8,16,,,,,+++++,+++,+++++,+++,2679,1,+++++,+++,+++++,+++,2700,1,,226ms,289ms,,58929us,276ms,118us,76us,61321us,198us,77us,21293us
# bonnie++ -d /data -s 32g -qfb
1.97,1.97,host57,1,1360852635,32G,,,,505977,54,151226,3,,,254450,3,257.0,8,16,,,,,+++++,+++,+++++,+++,2748,1,+++++,+++,+++++,+++,2602,1,,226ms,438ms,,373ms,1261ms,217us,84us,107ms,131us,31us,65746us
# bonnie++ -d /data -s 16g -qfb
1.97,1.97,host58,1,1360881644,16G,,,,478704,47,129047,4,,,330770,4,480.6,7,16,,,,,+++++,+++,+++++,+++,2195,2,+++++,+++,+++++,+++,2814,2,,373ms,389ms,,79935us,316ms,452us,82us,295ms,94us,169us,35213us
# bonnie++ -d /data -s 16g -qfb
1.97,1.97,host59,1,1360868560,16G,,,,396657,37,82812,1,,,246492,2,2800,43,16,,,,,+++++,+++,+++++,+++,2819,3,+++++,+++,+++++,+++,2761,1,,226ms,350ms,,90085us,70123us,582us,92us,61752us,135us,36us,13827us
Any help would be appreciated, as I just cannot find a way to translate those into the famed IOPS I am looking for.
The main idea here is to be able to find out if the 800 IOPS threshold is there or not on our future Splunk cluster.
Cheers,
Olivier
... View more
- Tags:
- iops
02-14-2013
05:33 AM
Well, that's not what is written in the bonnie++ man pages:
"NB You can specify the size in giga-bytes or the chunk-size in kilo-bytes if you add g or k to the end of the number respectively."
... View more