Deployment Architecture

How to sync data between two splunk servers

sureshsala
Explorer

I have few questions regarding splunk server data.
1. where does data is stored in splunk server, I am using universal forwarder to send the data to splunk.
2. How can i delete the data based on hostname. I want to delete all data based on the hostname
3. How can i sync the data between two splunk servers.

0 Karma

woodcock
Esteemed Legend

1: On your indexers, check here:

$SPLUNK_HOME/etc/system/{default|local}/indexes.conf

2: As far as hiding events from all further searches, like this:

My Search Details Here host=MyHostToDelete | delete

3: You can set up an indexer cluster with help here:

http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Clusterdeploymentoverview
http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Aboutclusters
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...