Hello, thanks for your answer
Let me clarify that I deployed the 3rd and last Billing Server allowed for CUCM for store and share raw CDRs for more than 1 tool. That's because Im not exporting CDRs directly to the Splunk Server (as you and the doc recommended)
I was testing R&A app this weekend on my Win7 Splunk setup, but:
1) I achieved to parse the CDRs and get the reports I wanted, but only if I downloaded it for the specific month. The idea is that Splunk and R&A app could read the CDRs directly from the CDR Repository , so I can avoid download CDRs every month. What I didnt understand yet is , ¿why you said that R&A could delete all CDRs only for reading or indexing them?? (even, for avoid any tool delete the CDRs from repository, I assigned read-only permissions for the shared folder, so it could be not possible for it delete them, and trying with Debian, R&A recognized the CDR path to the same shared folder, the only limitation was that I didnt have licensing for Splunk on Debian for allow index me all the CDR repository, aprox 20 GB). It could happen in the next release??
2) I also ended a bit concerned with the query performance for search in one Standalone Splunk (took too much time for read a 2.3 GB Montly CDR size), so it could be the opportunity to look for a Distributed Deployment (for speed up the query and report generation processes). I was reading those documents (https://docs.splunk.com/Documentation/Splunk/6.4.3/Admin/OptimizeSplunkforpeakperformance , http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Distributedoverview) but I dont know what could be a good good start point for improve R&A performance (¿¿How many forwarders, indexers, etc could I need???, Could split the load also in the Win7 CDR repository if i assign it a forward or index role??)
Regards.
... View more