Getting Data In

How to "add oneshot" to a cluster of indexers

jpincin
Engager

I want to import a large set of files, one time, into a cluster. Reading the documentation here:
http://docs.splunk.com/Documentation/Splunk/6.2.1/Data/MonitorfilesanddirectoriesusingtheCLI

It's not obvious to me how to specify all 20 index nodes that I want to target with the import. For monitored files, I use the outputs.conf to specify the 20 indexers and ports... I'm not sure how to replicate this with "add oneshot".

Any advice?

1 Solution

yannK
Splunk Employee
Splunk Employee

The recommended method is to setup a forwarder, configure the outputs,conf to loadbalance to them
then run the oneshot on the forwarder.

Otherwise, If the log are available from the indexers , you can use the oneshot on the one of the indexers and rely on the replication to later replicate the data accross the indexers.

View solution in original post

yannK
Splunk Employee
Splunk Employee

The recommended method is to setup a forwarder, configure the outputs,conf to loadbalance to them
then run the oneshot on the forwarder.

Otherwise, If the log are available from the indexers , you can use the oneshot on the one of the indexers and rely on the replication to later replicate the data accross the indexers.

jpincin
Engager

I configured the forwarder; working like a charm. Thanks!

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...