SlideShare a Scribd company logo
Distributed Management Console
Kam Amir – Sales Engineer
Mike Wilson – Sales Engineer
2
Personal Introduction
2
• Kamilo “Kam” Amir
• Works on the Splunk MidAtlantic Majors Team
• 4 years with Splunk, prior worked at BMC Software (BladeLogic) and Verizon
Business (Digex)
• Mike Wilson
• Works on Splunk Public Sector Team
• Yes, he works at Splunk for the last million years…
3
Agenda
• 6.4 DMC Recap
– Continuous Investment
– DMC Deployment Architectures
• So What’s Up With My Search Head Cluster?
• And that other Clustering thing, the Indexer Cluster?
• Indexes and Volumes Everywhere
• Forwarders (Really Everywhere)
• Oh, and One Other Thing…
3
4
Google
5
Blame
6
Try
7
Workaround
8
Answers
Distributed Management
Console 6.4 Recap
10
Continuous Investment in Management/Monitoring
• Started with Introspection in 6.1
• Items in 6.3 that will make Admins happy
– Data Integrity Control
– Forwarder Director
– Runaway Search Preventer
• The future
– Radically simplified setup/expansion
– Granular controls in distributed deployment
– Standard flows for common tasks in a distributed deployment
– Better App model for installation/management
1
11
History of Splunk Monitoring Tools
1
• index=_internal sourcetype=splunkd
– Go look at the logs!
• Splunkbase Tools
• Status/System Activity Dashboards
• Deployment Monitor
– License Usage Reporting!
– Alerting, Summarization
• S.o.S
– Developed by Splunk Support for Splunk Support and Customers
– Platform Resource Utilization collection with Technology Add-Ons
– Topology View
12
Distributed Management Console Architecture
1
Distributed Management Console Architecture
12
Search Heads/Search Head Cluster
Indexers/Index Cluster
Universal Forwarder
Distributed Search
Management
Data
DMC
Host
…
…
…
13
Setup Tasks
1
• Prerequisites
– Where does the DMC live?
– Topology Definition
– Forward all logs from all components back to the indexing tier
– All components must be Search Peers of the DMC Host
• Standalone vs Distributed Mode
– Server Roles
– Custom Groups
– Cluster Labels!
14 1
Search Head
Clustering Views
16
Search Head Clustering Views
1
• Motivation
– Plenty of data in logs/CLI
– Lots of customers deploying SHC
– What is going on in my Search Head
Cluster?
17 1
18 1
19 1
20 2
21 2
Index Clustering
Views
23
Indexer Clustering Views
2
• Motivation
– One layer deeper than originally
exposed
– Dealing with ever expanding
indexer counts
• Demo
24 2
25 2
Indexes & Volumes
View
27
Indexes and Volumes Views
2
• Motivation
– Customers love Fire Brigade
– Figuring out if you are meeting your
retention policies is tricky
• Demo
28 2
29 2
30 3
31 3
32 3
33 3
34 3
Forwarder
Monitoring Views
36
Forwarder Monitoring Views
3
• Motivation
– No Forwarder info in 6.2!
– Deployment Monitor no longer
improved/supported
– Some customers don’t use
Deployment Server
• Forwarder Monitoring Setup
– Runs a search against indexers
– Configurable period
– View reads from Asset Table
• Demo
37 3
38 3
39 3
Topology Views
41
Topology View
4
• Motivation
– Visual representation of
deployment
– Relationships between instances
– Deployment at-a-glance
– Troubleshooting
• Demo
42
KPI Overlays
4
43
Performance Overlays & Instance Details
4
44
DC Area Splunk Meetups
DC Area
• http://www.meetup.com/SplunkersDC/
• Q&A Chat forum
So what’s next on the agenda?
• April 27th 6:30pm McLean, VA – Happy
Splunk, Happy Splunker
45
SEPT 26-29, 2016
WALT DISNEY WORLD, ORLANDO
SWAN AND DOLPHIN RESORTS
• 5000+ IT & Business Professionals
• 3 days of technical content
• 165+ sessions
• 80+ Customer Speakers
• 35+ Apps in Splunk Apps Showcase
• 75+ Technology Partners
• 1:1 networking: Ask The Experts and Security
Experts, Birds of a Feather and Chalk Talks
• NEW hands-on labs!
• Expanded show floor, Dashboards Control
Room & Clinic, and MORE!
The 7th Annual Splunk Worldwide Users’ Conference
PLUS Splunk University
• Three days: Sept 24-26, 2016
• Get Splunk Certified for FREE!
• Get CPE credits for CISSP, CAP, SSCP
• Save thousands on Splunk education!
4
Thank You

More Related Content

What's hot (20)

PPTX
Splunk Dashboarding & Universal Vs. Heavy Forwarders
Harry McLaren
 
PPTX
Building Splunk Apps, Development Paths with Splunk & User Behaviour Analytics
Harry McLaren
 
PPTX
Splunk User Group Edinburgh - November Event
Harry McLaren
 
PPTX
How to Align Your Daily Splunk Activities Breakout Session
Splunk
 
PPTX
6.4 whats new
Splunk
 
PPTX
SplunkLive! Customer Presentation - Staples
Splunk
 
PPTX
A Vision for Transformation
Zenoss
 
PDF
Infrastructure monitoring made easy, from ingest to insight
Elasticsearch
 
PPTX
implementing the right website monitoring strategy
ManageEngine, Zoho Corporation
 
PDF
Keynote: Elastic Observability evolution and vision
Elasticsearch
 
PPTX
SplunkLive! Customer Presentation - Garmin International
Splunk
 
PPT
Fusion - BMC Service Assurance & Automation
jegasu
 
PDF
Combinación de logs, métricas y trazas para una observabilidad centralizada
Elasticsearch
 
PPTX
What's New in Splunk 6.3
Splunk
 
PDF
Construção de uma plataforma de observabilidade centralizada
Elasticsearch
 
PPTX
How to Design, Build and Map IT and Business Services in Splunk
Splunk
 
PDF
Combining logs, metrics, and traces for unified observability
Elasticsearch
 
PDF
Application Insights and Jupyter Notebook(Opensource) combo to analyze large ...
Sajeetharan
 
PPTX
AMSUG Presentation Nov 25, 2014
jmustac
 
PPT
Improving Reporting Performance
Dhiren Gala
 
Splunk Dashboarding & Universal Vs. Heavy Forwarders
Harry McLaren
 
Building Splunk Apps, Development Paths with Splunk & User Behaviour Analytics
Harry McLaren
 
Splunk User Group Edinburgh - November Event
Harry McLaren
 
How to Align Your Daily Splunk Activities Breakout Session
Splunk
 
6.4 whats new
Splunk
 
SplunkLive! Customer Presentation - Staples
Splunk
 
A Vision for Transformation
Zenoss
 
Infrastructure monitoring made easy, from ingest to insight
Elasticsearch
 
implementing the right website monitoring strategy
ManageEngine, Zoho Corporation
 
Keynote: Elastic Observability evolution and vision
Elasticsearch
 
SplunkLive! Customer Presentation - Garmin International
Splunk
 
Fusion - BMC Service Assurance & Automation
jegasu
 
Combinación de logs, métricas y trazas para una observabilidad centralizada
Elasticsearch
 
What's New in Splunk 6.3
Splunk
 
Construção de uma plataforma de observabilidade centralizada
Elasticsearch
 
How to Design, Build and Map IT and Business Services in Splunk
Splunk
 
Combining logs, metrics, and traces for unified observability
Elasticsearch
 
Application Insights and Jupyter Notebook(Opensource) combo to analyze large ...
Sajeetharan
 
AMSUG Presentation Nov 25, 2014
jmustac
 
Improving Reporting Performance
Dhiren Gala
 

Similar to Splunk Distributed Management Console (20)

PPTX
Distributed Management Console Breakout Session
Splunk
 
PPTX
Taking Splunk to the Next Level - Architecture Breakout Session
Splunk
 
PPTX
Taking Splunk to the Next Level - Architecture Breakout Session
Splunk
 
PPTX
Taking Splunk to the Next Level - Architecture Breakout Session
Splunk
 
PPTX
Taking Splunk to the Next Level - Architecture
Splunk
 
PPTX
Taking Splunk to the Next Level – Architecture
Splunk
 
PPTX
Taking Splunk to the Next Level - Architecture Breakout Session
Splunk
 
PPTX
Getting Started with Splunk Breakout Session
Splunk
 
PPTX
Taking Splunk to the Next Level - Architecture
Splunk
 
PPTX
Taking Splunk to the Next Level - Architecture Breakout Session
Splunk
 
PPTX
Getting Started with Splunk Enterprise Hands-On
Splunk
 
PPTX
Taking Splunk to the Next Level – Architecture
Splunk
 
PPTX
Taking Splunk to the Next Level - Technical
Splunk
 
PPTX
Taking Splunk to the Next Level - Architecture Breakout Session
Splunk
 
PPTX
Getting Started with Splunk Breakout Session
Splunk
 
PPTX
Getting Started with Splunk Enterprise
Shannon Cuthbertson
 
PPTX
Getting Started with Splunk Enterprise
Splunk
 
PDF
Getting Started with Splunk Enterprise
Splunk
 
PPTX
Getting Started with Splunk Enterprises
Splunk
 
PDF
Getting Started with Splunk Enterprise
Splunk
 
Distributed Management Console Breakout Session
Splunk
 
Taking Splunk to the Next Level - Architecture Breakout Session
Splunk
 
Taking Splunk to the Next Level - Architecture Breakout Session
Splunk
 
Taking Splunk to the Next Level - Architecture Breakout Session
Splunk
 
Taking Splunk to the Next Level - Architecture
Splunk
 
Taking Splunk to the Next Level – Architecture
Splunk
 
Taking Splunk to the Next Level - Architecture Breakout Session
Splunk
 
Getting Started with Splunk Breakout Session
Splunk
 
Taking Splunk to the Next Level - Architecture
Splunk
 
Taking Splunk to the Next Level - Architecture Breakout Session
Splunk
 
Getting Started with Splunk Enterprise Hands-On
Splunk
 
Taking Splunk to the Next Level – Architecture
Splunk
 
Taking Splunk to the Next Level - Technical
Splunk
 
Taking Splunk to the Next Level - Architecture Breakout Session
Splunk
 
Getting Started with Splunk Breakout Session
Splunk
 
Getting Started with Splunk Enterprise
Shannon Cuthbertson
 
Getting Started with Splunk Enterprise
Splunk
 
Getting Started with Splunk Enterprise
Splunk
 
Getting Started with Splunk Enterprises
Splunk
 
Getting Started with Splunk Enterprise
Splunk
 
Ad

More from Splunk (20)

PDF
Splunk Leadership Forum Wien - 20.05.2025
Splunk
 
PDF
Splunk Security Update | Public Sector Summit Germany 2025
Splunk
 
PDF
Building Resilience with Energy Management for the Public Sector
Splunk
 
PDF
IT-Lagebild: Observability for Resilience (SVA)
Splunk
 
PDF
Nach dem SOC-Aufbau ist vor der Automatisierung (OFD Baden-Württemberg)
Splunk
 
PDF
Monitoring einer Sicheren Inter-Netzwerk Architektur (SINA)
Splunk
 
PDF
Praktische Erfahrungen mit dem Attack Analyser (gematik)
Splunk
 
PDF
Cisco XDR & Splunk SIEM - stronger together (DATAGROUP Cyber Security)
Splunk
 
PDF
Security - Mit Sicherheit zum Erfolg (Telekom)
Splunk
 
PDF
One Cisco - Splunk Public Sector Summit Germany April 2025
Splunk
 
PDF
.conf Go 2023 - Data analysis as a routine
Splunk
 
PDF
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
Splunk
 
PDF
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
Splunk
 
PDF
.conf Go 2023 - Raiffeisen Bank International
Splunk
 
PDF
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
Splunk
 
PDF
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
Splunk
 
PDF
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
Splunk
 
PDF
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
Splunk
 
PDF
.conf go 2023 - De NOC a CSIRT (Cellnex)
Splunk
 
PDF
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
Splunk
 
Splunk Leadership Forum Wien - 20.05.2025
Splunk
 
Splunk Security Update | Public Sector Summit Germany 2025
Splunk
 
Building Resilience with Energy Management for the Public Sector
Splunk
 
IT-Lagebild: Observability for Resilience (SVA)
Splunk
 
Nach dem SOC-Aufbau ist vor der Automatisierung (OFD Baden-Württemberg)
Splunk
 
Monitoring einer Sicheren Inter-Netzwerk Architektur (SINA)
Splunk
 
Praktische Erfahrungen mit dem Attack Analyser (gematik)
Splunk
 
Cisco XDR & Splunk SIEM - stronger together (DATAGROUP Cyber Security)
Splunk
 
Security - Mit Sicherheit zum Erfolg (Telekom)
Splunk
 
One Cisco - Splunk Public Sector Summit Germany April 2025
Splunk
 
.conf Go 2023 - Data analysis as a routine
Splunk
 
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
Splunk
 
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
Splunk
 
.conf Go 2023 - Raiffeisen Bank International
Splunk
 
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
Splunk
 
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
Splunk
 
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
Splunk
 
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
Splunk
 
.conf go 2023 - De NOC a CSIRT (Cellnex)
Splunk
 
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
Splunk
 
Ad

Recently uploaded (20)

PPTX
Simple and concise overview about Quantum computing..pptx
mughal641
 
PDF
How ETL Control Logic Keeps Your Pipelines Safe and Reliable.pdf
Stryv Solutions Pvt. Ltd.
 
PPTX
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
PDF
Per Axbom: The spectacular lies of maps
Nexer Digital
 
PDF
Peak of Data & AI Encore - Real-Time Insights & Scalable Editing with ArcGIS
Safe Software
 
PDF
CIFDAQ's Market Wrap : Bears Back in Control?
CIFDAQ
 
PDF
Structs to JSON: How Go Powers REST APIs
Emily Achieng
 
PDF
GDG Cloud Munich - Intro - Luiz Carneiro - #BuildWithAI - July - Abdel.pdf
Luiz Carneiro
 
PPTX
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
 
PDF
The Future of Artificial Intelligence (AI)
Mukul
 
PDF
Brief History of Internet - Early Days of Internet
sutharharshit158
 
PPTX
Agile Chennai 18-19 July 2025 | Workshop - Enhancing Agile Collaboration with...
AgileNetwork
 
PDF
Market Insight : ETH Dominance Returns
CIFDAQ
 
PDF
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
 
PDF
Trying to figure out MCP by actually building an app from scratch with open s...
Julien SIMON
 
PPTX
Farrell_Programming Logic and Design slides_10e_ch02_PowerPoint.pptx
bashnahara11
 
PDF
State-Dependent Conformal Perception Bounds for Neuro-Symbolic Verification
Ivan Ruchkin
 
PDF
Tea4chat - another LLM Project by Kerem Atam
a0m0rajab1
 
PDF
Generative AI vs Predictive AI-The Ultimate Comparison Guide
Lily Clark
 
PPTX
IT Runs Better with ThousandEyes AI-driven Assurance
ThousandEyes
 
Simple and concise overview about Quantum computing..pptx
mughal641
 
How ETL Control Logic Keeps Your Pipelines Safe and Reliable.pdf
Stryv Solutions Pvt. Ltd.
 
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
Per Axbom: The spectacular lies of maps
Nexer Digital
 
Peak of Data & AI Encore - Real-Time Insights & Scalable Editing with ArcGIS
Safe Software
 
CIFDAQ's Market Wrap : Bears Back in Control?
CIFDAQ
 
Structs to JSON: How Go Powers REST APIs
Emily Achieng
 
GDG Cloud Munich - Intro - Luiz Carneiro - #BuildWithAI - July - Abdel.pdf
Luiz Carneiro
 
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
 
The Future of Artificial Intelligence (AI)
Mukul
 
Brief History of Internet - Early Days of Internet
sutharharshit158
 
Agile Chennai 18-19 July 2025 | Workshop - Enhancing Agile Collaboration with...
AgileNetwork
 
Market Insight : ETH Dominance Returns
CIFDAQ
 
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
 
Trying to figure out MCP by actually building an app from scratch with open s...
Julien SIMON
 
Farrell_Programming Logic and Design slides_10e_ch02_PowerPoint.pptx
bashnahara11
 
State-Dependent Conformal Perception Bounds for Neuro-Symbolic Verification
Ivan Ruchkin
 
Tea4chat - another LLM Project by Kerem Atam
a0m0rajab1
 
Generative AI vs Predictive AI-The Ultimate Comparison Guide
Lily Clark
 
IT Runs Better with ThousandEyes AI-driven Assurance
ThousandEyes
 

Splunk Distributed Management Console

  • 1. Distributed Management Console Kam Amir – Sales Engineer Mike Wilson – Sales Engineer
  • 2. 2 Personal Introduction 2 • Kamilo “Kam” Amir • Works on the Splunk MidAtlantic Majors Team • 4 years with Splunk, prior worked at BMC Software (BladeLogic) and Verizon Business (Digex) • Mike Wilson • Works on Splunk Public Sector Team • Yes, he works at Splunk for the last million years…
  • 3. 3 Agenda • 6.4 DMC Recap – Continuous Investment – DMC Deployment Architectures • So What’s Up With My Search Head Cluster? • And that other Clustering thing, the Indexer Cluster? • Indexes and Volumes Everywhere • Forwarders (Really Everywhere) • Oh, and One Other Thing… 3
  • 10. 10 Continuous Investment in Management/Monitoring • Started with Introspection in 6.1 • Items in 6.3 that will make Admins happy – Data Integrity Control – Forwarder Director – Runaway Search Preventer • The future – Radically simplified setup/expansion – Granular controls in distributed deployment – Standard flows for common tasks in a distributed deployment – Better App model for installation/management 1
  • 11. 11 History of Splunk Monitoring Tools 1 • index=_internal sourcetype=splunkd – Go look at the logs! • Splunkbase Tools • Status/System Activity Dashboards • Deployment Monitor – License Usage Reporting! – Alerting, Summarization • S.o.S – Developed by Splunk Support for Splunk Support and Customers – Platform Resource Utilization collection with Technology Add-Ons – Topology View
  • 12. 12 Distributed Management Console Architecture 1 Distributed Management Console Architecture 12 Search Heads/Search Head Cluster Indexers/Index Cluster Universal Forwarder Distributed Search Management Data DMC Host … … …
  • 13. 13 Setup Tasks 1 • Prerequisites – Where does the DMC live? – Topology Definition – Forward all logs from all components back to the indexing tier – All components must be Search Peers of the DMC Host • Standalone vs Distributed Mode – Server Roles – Custom Groups – Cluster Labels!
  • 14. 14 1
  • 16. 16 Search Head Clustering Views 1 • Motivation – Plenty of data in logs/CLI – Lots of customers deploying SHC – What is going on in my Search Head Cluster?
  • 17. 17 1
  • 18. 18 1
  • 19. 19 1
  • 20. 20 2
  • 21. 21 2
  • 23. 23 Indexer Clustering Views 2 • Motivation – One layer deeper than originally exposed – Dealing with ever expanding indexer counts • Demo
  • 24. 24 2
  • 25. 25 2
  • 27. 27 Indexes and Volumes Views 2 • Motivation – Customers love Fire Brigade – Figuring out if you are meeting your retention policies is tricky • Demo
  • 28. 28 2
  • 29. 29 2
  • 30. 30 3
  • 31. 31 3
  • 32. 32 3
  • 33. 33 3
  • 34. 34 3
  • 36. 36 Forwarder Monitoring Views 3 • Motivation – No Forwarder info in 6.2! – Deployment Monitor no longer improved/supported – Some customers don’t use Deployment Server • Forwarder Monitoring Setup – Runs a search against indexers – Configurable period – View reads from Asset Table • Demo
  • 37. 37 3
  • 38. 38 3
  • 39. 39 3
  • 41. 41 Topology View 4 • Motivation – Visual representation of deployment – Relationships between instances – Deployment at-a-glance – Troubleshooting • Demo
  • 43. 43 Performance Overlays & Instance Details 4
  • 44. 44 DC Area Splunk Meetups DC Area • http://www.meetup.com/SplunkersDC/ • Q&A Chat forum So what’s next on the agenda? • April 27th 6:30pm McLean, VA – Happy Splunk, Happy Splunker
  • 45. 45 SEPT 26-29, 2016 WALT DISNEY WORLD, ORLANDO SWAN AND DOLPHIN RESORTS • 5000+ IT & Business Professionals • 3 days of technical content • 165+ sessions • 80+ Customer Speakers • 35+ Apps in Splunk Apps Showcase • 75+ Technology Partners • 1:1 networking: Ask The Experts and Security Experts, Birds of a Feather and Chalk Talks • NEW hands-on labs! • Expanded show floor, Dashboards Control Room & Clinic, and MORE! The 7th Annual Splunk Worldwide Users’ Conference PLUS Splunk University • Three days: Sept 24-26, 2016 • Get Splunk Certified for FREE! • Get CPE credits for CISSP, CAP, SSCP • Save thousands on Splunk education!

Editor's Notes

  • #4: Stela goes over the agenda
  • #13: Obvious questions about what can be co-hosted. What does Splunk look like when it gets big?
  • #15: A typical DMC setup page
  • #18: The Status and Configuration dashboard is an overview of your search head cluster. It is high-level information.
  • #19: The Configuration Replication dashboard provides insight into configurations that a user changes on any SHC member, and how these changes propagate through the cluster.
  • #20: The Artifact Replication dashboard contains several panels describing the cluster's "backlog" of search artifacts to replicate.
  • #21: Provides visibility into the captain’s role as a coordinator for scheduled searches in the cluster.
  • #22: In the Apps status panel, a persistent discrepancy indicates that the deployer has not finished deploying apps to its members.
  • #25: 2 indexes, 1 status view The status of several indexer clusters can now be consulted from a single location! No need to connect to several Cluster Master instances
  • #26: This view shows service tasks undertaken by the indexer clustering framework to meet data replication targets The marker shows a time when an indexer went down, requiring the surviving ones to start copying data buckets to repair the cluster We clearly see an initial peak of fix-up tasks identified, which slowly decreases over time as the cluster fixes itself In that manner, this view provides visibility into the progress of such unplanned reconfiguration events
  • #29: We’re looking at the _audit index on the ‘potato’ indexer cluster. We have a target time retention of 150 days for this index, which seems to be respected based on this ‘median data age’ metric.
  • #30: However, looking at the breakdown of data age per indexer, we can see that one indexer (svdev-centos6-006.sv.splunk.com) does not meet the target of 150 days of retention. To investigate further, we click on the table row corresponding to this index, which leads us to the Index Detail – Instance view.
  • #31: Looking in detail at the index that fails to meet the target retention for the _audit index, we see that: Data is not being deleted due to hitting the time-based retention policy (1st column) Data is not being deleted due to hitting the index-wide disk usage retention policy (2nd column) Data is not being deleted due to hitting directory-level (home & cold path) retention policies (3rd and 4th columns)
  • #32: Looking at how data age evolved over time, we can see a sharp drop-off on 09/08, indicating an incident on that day Furthermore, we see that on 09/08 we lost almost all cold buckets, indicating that something happened to the cold directory of this index on that day Let’s take a closer look at the settings for this index: Is this leveraging volumes?
  • #33: Indeed, both paths for this index are referencing volumes homePath (hot + warm buckets) is referencing a volume named “opt” coldPath (cold buckets) is referencing a volume named “cold” We should look at these volumes next, using the Volume Detail – Instance scoped to this indexer
  • #34: First let’s look at the ‘opt’ volume We see that this volume is _not_ full, so it’s not pushing data out We also see that the _audit index’s ‘home’ directory is hosted on this volume, with ~3GB worth of data Let’s move on to the ‘cold’ volume
  • #35: Looking at the ‘cold’ volume now This volume *is* full! It is pushing data out aggressively! All space in this volume is used by the ‘latex_imports’ index, representing only ~ 1 day’s worth of data Given that a full volume freezes older data first, the surge of recent data from ‘latex_imports’ has caused the volume to push out all data from the ‘_audit’ index Solution: separate indexes with different data density and target retention periods in different volumes
  • #38: Forwarder Monitoring – Deployment view can highlight missing forwarders Here we can clearly see two forwarders that have gone missing The first one – ‘atruong-mbpr15’ – hasn’t sent data to the indexers for ~ 3 hours The second one – ‘uf-dmcdemo’ – hasn’t sent data to the indexers for ~ 13 hours Let’s click on one of these missing forwarders for a drill-down to the Forwarder Monitoring – Instance view
  • #39: Forwarder Monitoring – Instance view We’re now looking in more detail at the history of forwarder ‘uf-dmcdemo’ connections to the indexers on the previous day We can clearly see a gap of several hours during which this forwarder did not connect to the indexers, which would have resulted in a “missing” status
  • #40: Missing forwarders can also be pro-actively detected using a built-in alert!
  • #46: We’re headed to the East Coast! 2 inspired Keynotes – General Session and Security Keynote + Super Sessions with Splunk Leadership in Cloud, IT Ops, Security and Business Analytics! 165+ Breakout sessions addressing all areas and levels of Operational Intelligence – IT, Business Analytics, Mobile, Cloud, IoT, Security…and MORE! 30+ hours of invaluable networking time with industry thought leaders, technologists, and other Splunk Ninjas and Champions waiting to share their business wins with you! Join the 50%+ of Fortune 100 companies who attended .conf2015 to get hands on with Splunk. You’ll be surrounded by thousands of other like-minded individuals who are ready to share exciting and cutting edge use cases and best practices. You can also deep dive on all things Splunk products together with your favorite Splunkers. Head back to your company with both practical and inspired new uses for Splunk, ready to unlock the unimaginable power of your data! Arrive in Orlando a Splunk user, leave Orlando a Splunk Ninja! REGISTRATION OPENS IN MARCH 2016 – STAY TUNED FOR NEWS ON OUR BEST REGISTRATION RATES – COMING SOON!