Quantcast
Channel: Questions in topic: "heavy-forwarder"
Browsing all 727 articles
Browse latest View live
↧

how can i enable forwarding using a heavy forwarder with outputs.conf?

Actually I want to ask that what is the equivalent of this command?: splunk enable app SplunkForwarder -auth : I saw the `indexAndForward` option, but it's not the equivalent the command above, isn't...

View Article


How to set up a heavy forwarder to forward data to Splunk Cloud?

HI! I am setting-up a heavy forwarder to forward data to Splunk Cloud. Do I just follow the instructions for setting-up a Universal forwarder to forward to Splunk Cloud? What address do I use as my...

View Article


My Splunk Add-on for Check Point OPSEC LEA configuration works on an indexer,...

I am trying to deploy the Splunk Add-on for Check Point OPSEC LEA on a heavy forwarder and the configuration is not working. I tried it on the indexer directly and it worked, but when I try to...

View Article

Is there a comparison of CPU consumption of HF and UF?

hi all, I want to use splunk heavy forwarder in my company but i wonder that what does it cost me to use HF? Is there any test or something like that about cpu, IO consuming etc. ?

View Article

Is SPL-79009 solved ?

I have the same issue than SPL-79009 on heavy forwarder 6.5.1 with http event collector ... _TCP_ROUTING set in inputs.conf is not applied (data are still sent to defaultgroup)

View Article


Is there a test to compare CPU and memory consumption of a heavy forwarder...

hi all, I want to use a Splunk heavy forwarder in my company, but I wonder that what does it cost me to use a HF? Is there any test or something like that about cpu, IO consuming etc. ?

View Article

Is SPL-79009 solved? Heavy forwarder 6.5.1 with HTTP Event Collector:...

I have the same issue as SPL-79009 on a 6.5.1 heavy forwarder with http event collector ... _TCP_ROUTING set in inputs.conf is not applied (data are still sent to defaultgroup)

View Article

How to distribute splunk.secret to Windows Heavy Forwarders

Hello guys, we are going to install two Heavy Forwarders on Windows 2012 R2 servers. The remaining instances of Splunk, which build-up our distributed architecture, are running on SLES. As usual,...

View Article


Splunk DB Connect: How to resolve "Failed to initialize pool: Login failed...

HI, I have Splunk DB Connect install on a Splunk heavy forwarder. I am having trouble connecting to the database. The person who setup the DB has confirmed that the username and password are correct....

View Article


Why is one Splunk forwarder not reporting in, but the splunkd service is...

For analyzing the issue, I went for splunkd.log file in my forwarder: It reads as the following (a certain part): 12-01-2016 03:49:59.902 -0500 INFO TailReader - File descriptor cache is full (100),...

View Article

Why am I unable to forward data from a Splunk forwarder to Splunk Cloud on...

Hello, I have been trying for the last 8 hours to forward data to a Splunk Cloud instance. I generated the credentials off the Splunk Cloud instance as directed and attempted to use them on a heavy...

View Article

How to route to an Index based on SourceType AND Host combination in...

I have a setup as Universal Forwarder (UF) - Heavy Forwarder (HF) - Indexer - Search Head (SH). Where multiple UF are sending data to single HF which in turn sends data to single Indexer. I have below...

View Article

Should the hardware on my Heavy Forwarder be the same as my Indexer?

My current system is (vastly underpowered, 3.5gig a day tops) a single indexer/search head combo, and 2 heavy forwarders. I have recently been given a requirement to bump this up to ~120GB a day...

View Article


What is the best way to collect and monitor Windows 2008 R2 print server events?

I'd like to track print events from a Windows 2008 R2 print server. I have configured my Universal Forwarder (UF) via this blog: http://blogs.splunk.com/2014/04/21/windows-print-monitoring-in-splunk-6/...

View Article

How to blacklist two different hosts in inputs.conf?

Hi All, Can any one guide me on how to blacklist two different host in the same inputs.conf files in Heavy Forwarder (HF) instance? Currently we have the below inputs.conf set and in which we have...

View Article


Measuring thruput of heavy forwarders in a dashboard. Would using...

Hi, Quick question regarding metrics.log and a heavy forwarder (HF). I'm using a dashboard to measure the thruput on a few HF's and was curious if using `metrics.log group=thruput name=thruput` adds...

View Article

Splunk Stream: Why does my heavy forwarder not show up in the Distributed...

Hi, I'm about to pull what little hair I have left out. I have a SH and Indexer Cluster running 6.5.1. My cluster uses our own SSL certs for server.conf, web.conf, and inputs.conf, which appear to be...

View Article


Splunk DB Connect 2.3.0: How to automatically re-enable DBX operations after...

I am running version 2.3.0 and have a problem I would like to work around. When one of my DB servers gets taken offline for maintenance, and there is a Splunk DB Connect operation that would access it,...

View Article

Splunk DB Connect: How do I synchronize lookup tables across search heads?

Splunk DB Connect 2 installed on a heavy forwarder, dbxquery creates a lookup table (see below), my search heads needs to access lookup table. **Splunk Lookup Table Creation Command** | dbxquery...

View Article

Splunk Add-on for Kafka: How to send topic messages to my indexer ?

1)I tried first option of manage inputs from a single node via a Search Head Cluster and I'm not getting any any topic messages in UI. Why is this so? I gave the kafka cluster details and Heavy...

View Article
Browsing all 727 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>