Quantcast
Channel: Questions in topic: "distributed-search"
Browsing all 180 articles
Browse latest View live

Where do I install the SNMP Modular Input in a search head clustering...

Hi all, We have a distributed Splunk environment where we have clustered search heads, indexes, heavy forwarders, and universal forwarders. I would like to know where would I need to install the SNMP...

View Article


What would be the best practice for creating indexes in our distributed...

I'm looking to get information on what is the best way to make indexes for data. Background: Setting up a clustered environment with both cluster indexers (replication factor 3) and clustered...

View Article


Will uninstalling a search head from a distributed search environment using...

We have a distributed Splunk Enterprise environment running 6.1. There are two search heads. I believe the original goal was to set up search head pooling. Before I upgrade to 6.2.x, I'd like to clean...

View Article

SNMP Modular Input: Is it required to restart Splunk after adding new SNMP...

Hi All, In our test environment, we have search head, a pair of Indexer clusters, a master node, and a heavy forwarder running Splunk 6.2.2. I have successfully installed the SNMP Modular input on the...

View Article

Used deployer to distribute django tutorial to search head cluster

So I followed the tutorial for splunk django framework. Completed it and it worked fine when testing. I then tested out the deployer process to learn how to take something like that and put it on...

View Article


Error while distributing configuration bundle (SA_Utils and Splunk_TA_vmware)...

We have set up a **distributed architecture** for **splunk app for vmware**. Architecture components: 1 Master node, 1 SH (which has scheduler setup), 2 Indexers, 1 Forwarder (which is the DCN). While...

View Article

After adding a new Splunk server in a distributed environment, why does it...

I recently added a new splunk server in a distributed environment. Now, when I do this search: index=os earliest="09/01/2015:09:30:00" latest="09/01/2015:09:35:00" | timechart count by splunk_server...

View Article

How to change the index for the Splunk App and Add-on for Unix and Linux...

We are in the process of deploying the Splunk App for Unix and Linux on our Linux servers in a distributed Splunk environment. I was able to successfully change the indexer from the default (os) to the...

View Article


How will the S.o.S. - Splunk on Splunk app impact my license usage in a...

I tried to search this, but didn't seem to find an answer. I understand that all the logs that come to a Splunk Indexer from _INTERNAL does not count under Splunk licensing. I have a distributed...

View Article


Why isn't my index available for search in a distributed search environment?

Hi to everyone I have a "Distributed Environment", with two indexers, and two search heads. In the Master Node Indexer, I have an index called ftp, with a lot of data (I want this data available for...

View Article

After installing Cisco Security Suite, why am I getting "KeyError:...

I've installed Cisco Security Suite 3.1.1 on my Splunk Enterprise search head and restarted Splunk. When prompted to run the setup, I get an error message: KeyError: 'elements' View more information...

View Article

Does decrypt work in distributed search environments?

I can get this app to work fine, if I'm running in locally on an indexer. But not from a distributed search head. index=_internal | decrypt field=sourcetype hex() emit('sourcetype') Corresponding...

View Article

Distributed Search: Is it possible to configure a search head to search a...

I'm having a hard time finding anything regarding this setup, so I'm trying my luck here. Is it possible to configure a Search Head to search a remote Search Head that is within a cluster environment?...

View Article


Why is the splunkd.log reporting lots of "DistributedPeerManager - Unable to...

I have a very busy search head that complains : DistributedPeerManager - Unable to distribute to peer named slxxxxxxxxx:9089 at uri https://xxxxxxxx037:9089 because peer has status = "Down" The...

View Article

Distributed Search Replication Failure after 6.3 upgrade with error...

I've seen a few related issues on Answers, but not this specific error. I have a deployment with a single search head, two indexers, and a cluster master. After upgrading to 6.3, my search head can no...

View Article


What would be the best practice for creating indexes in our distributed...

I'm looking to get information on what is the best way to make indexes for data. Background: Setting up a clustered environment with both cluster indexers (replication factor 3) and clustered...

View Article

Will uninstalling a search head from a distributed search environment using...

We have a distributed Splunk Enterprise environment running 6.1. There are two search heads. I believe the original goal was to set up search head pooling. Before I upgrade to 6.2.x, I'd like to clean...

View Article


SNMP Modular Input: Is it required to restart Splunk after adding new SNMP...

Hi All, In our test environment, we have search head, a pair of Indexer clusters, a master node, and a heavy forwarder running Splunk 6.2.2. I have successfully installed the SNMP Modular input on the...

View Article

Used deployer to distribute django tutorial to search head cluster

So I followed the tutorial for splunk django framework. Completed it and it worked fine when testing. I then tested out the deployer process to learn how to take something like that and put it on...

View Article

Error while distributing configuration bundle (SA_Utils and Splunk_TA_vmware)...

We have set up a **distributed architecture** for **splunk app for vmware**. Architecture components: 1 Master node, 1 SH (which has scheduler setup), 2 Indexers, 1 Forwarder (which is the DCN). While...

View Article
Browsing all 180 articles
Browse latest View live


Latest Images