Deployment Architecture

How to sync data between two splunk servers

sureshsala
Explorer

I have few questions regarding splunk server data.
1. where does data is stored in splunk server, I am using universal forwarder to send the data to splunk.
2. How can i delete the data based on hostname. I want to delete all data based on the hostname
3. How can i sync the data between two splunk servers.

0 Karma

woodcock
Esteemed Legend

1: On your indexers, check here:

$SPLUNK_HOME/etc/system/{default|local}/indexes.conf

2: As far as hiding events from all further searches, like this:

My Search Details Here host=MyHostToDelete | delete

3: You can set up an indexer cluster with help here:

http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Clusterdeploymentoverview
http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Aboutclusters
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...