Splunk Distributed Search Setup & Configuration

แชร์
ฝัง
  • เผยแพร่เมื่อ 4 พ.ย. 2024

ความคิดเห็น • 24

  • @rohitbiswaslit93
    @rohitbiswaslit93 5 ปีที่แล้ว +1

    Question- I hope this will not be required once we integrate shc with indexer cluster as explained in your future videos.

    • @splunk_ml
      @splunk_ml  5 ปีที่แล้ว

      Yes correct.

  • @CHAMP_GUY
    @CHAMP_GUY 3 ปีที่แล้ว

    Perfect. Please make a tutorial for syslog-ng with universal or heavy forwarder or HEC

  • @MrChanni8
    @MrChanni8 2 ปีที่แล้ว

    Hi sir can it be that in peers since ssl config is not setup to allow https Uris that is why its not taking with schema ?

  • @badrib6669
    @badrib6669 5 ปีที่แล้ว

    Good One, Thank you.

  • @ramaprrasad.m3940
    @ramaprrasad.m3940 5 ปีที่แล้ว

    How to collect network logs by heavy forwaders.
    2.What are the steps to configure syslog server by using heavy forwarder,and how to forward network logs

    • @splunk_ml
      @splunk_ml  5 ปีที่แล้ว

      Please have a look at the below link,
      answers.splunk.com/answers/252547/how-to-configure-logging-from-network-devices-fire.html

  • @ninhtran4322
    @ninhtran4322 5 ปีที่แล้ว

    so helpful, thanks U

  • @cainiak
    @cainiak 4 ปีที่แล้ว

    Good video

  • @陳志奕-w7m
    @陳志奕-w7m 4 ปีที่แล้ว

    Hello sir,I have the error when I added the search peers
    [Encountered the following error while trying to save: Error while sending public key to search peer: Connect Timeout] =>On the web
    [Error while sending public key to search peer: Connect Timeout] =>On the command
    Which step did I go wrong
    Thanks~

    • @splunk_ml
      @splunk_ml  4 ปีที่แล้ว

      Can you check the firewall settings. Looks like Indexer is not reachable.

  • @penchum6722
    @penchum6722 4 ปีที่แล้ว

    I am using AWS When I created distributed peers-Search peer ip-172-31-34-22.us-east-2.compute.internal has the following message: Now skipping indexing of internal audit events, because the downstream queue is not accepting data. Will keep dropping events until data flow resumes. Review system health: ensure downstream indexing and/or forwarding are operating correctly.

  • @kundankumarsaraf3563
    @kundankumarsaraf3563 4 ปีที่แล้ว

    Please help me. How you have created three instances acting as a Indexers and One intsance acting as a Search Head?

    • @splunk_ml
      @splunk_ml  4 ปีที่แล้ว

      you can refer the below video for splunk installation in GCP ubuntu instance.
      th-cam.com/video/dt4gR5AcMo0/w-d-xo.html

    • @kundankumarsaraf3563
      @kundankumarsaraf3563 4 ปีที่แล้ว

      @@splunk_ml Thank you very much for your kind reply.

  • @HKSHAH1000
    @HKSHAH1000 3 ปีที่แล้ว

    Any strong reason for using distributed search

  • @Sarj0129
    @Sarj0129 4 ปีที่แล้ว

    Bro, Can you do a video on Correlation rules !!!

  • @RavindraKumarSG
    @RavindraKumarSG 4 ปีที่แล้ว

    can we have just one indexer and one search head

    • @splunk_ml
      @splunk_ml  4 ปีที่แล้ว

      Off course you can have. That is basic of distributed search.

    • @RavindraKumarSG
      @RavindraKumarSG 4 ปีที่แล้ว

      @@splunk_ml Thanks buddy. Your videos are very nice .. You are very patient too. Keep it up friend.

  • @ramaprrasad.m3940
    @ramaprrasad.m3940 5 ปีที่แล้ว

    If cluster master failed.then how to troubleshoot.

    • @splunk_ml
      @splunk_ml  5 ปีที่แล้ว

      Please have a look at the below link,
      docs.splunk.com/Documentation/Splunk/7.3.0/Indexer/Whathappenswhenamasternodegoesdown

  • @grainfrizz
    @grainfrizz 5 ปีที่แล้ว

    https will work when ssl is on

    • @splunk_ml
      @splunk_ml  5 ปีที่แล้ว

      It's not related to ssl... Even http didn't work... Give it a try