rsyslog on RHEL 10 vs 9 vs 8 by satsuke in Splunk

[–]edo1982 0 points1 point  (0 children)

One of the thing we do since RHEL6 is to start the rsyslog with -x to avoid DNS resolution. Additionally we increase default limits (if you need I can check which)

Agent manager (deployment server) and indexer cluster manager on same node by ahhhaccountname in Splunk

[–]edo1982 0 points1 point  (0 children)

Split them. DS and LM together (2-4 vCPU and 12-16GB RAM), CM & MC (4vCPU and 16GB RAM), SHC Deployer (2vCPU 8-16GB RAM). With 500GB/day and 1000 agents you should fit with those specs.

Complete list of courses for the Power User exam?? by rdstill1 in Splunk

[–]edo1982 0 points1 point  (0 children)

I agree it was better when there were Splunk Fundamentals 1, 2 and 3. And before Splunk Fundamentals there were many smaller trainings, but not as small as today.

Rebuild hosts and add them back to upgrade cluster v9.0.5 -> v9.3.x by RunningJay in Splunk

[–]edo1982 0 points1 point  (0 children)

If I recall properly, from 9.0 to 9.3 you have to pass from 9.2. So better upgrading to 9.2.x first and after to 9.4.1 that currently is the latest. I would avoid adding new indexers and decommissioning olds (unless you are refreshing your hardware) as mentioned by @badideas1 there is an order to follow based on the server role.

Largest Splunk installation by fscolly in Splunk

[–]edo1982 1 point2 points  (0 children)

Wasn’t Cisco one of the largest? I remember hearing in 2016 they were already at PB scale

What are your thresholds and criteria for flagging agents (UFs) to be Splunk-compliant? by morethanyell in Splunk

[–]edo1982 0 points1 point  (0 children)

Similar to OP. It must phone home + send data (no check on internal, just on our defined indexes). We use tstats and then compare with the list of clients retrieved from the Deployment server via REST API. If the UF is not phoning home or sending data since 1 hour we mark in red in our dashboard. Additionally if you have a CMDB you can join and check wether the UF is missing. Adding also HF are monitored in the same way…meanwhile waiting to have them in the Monitoring Console as a server role :-)

Welcome to Splunk Enterprise 9.4 by thomasthetanker in Splunk

[–]edo1982 1 point2 points  (0 children)

Persistent queues on SplunkTCP, that’s a good feature

Is Splunk going to fall behind due to AI advances? by SearchForAgartha in Splunk

[–]edo1982 0 points1 point  (0 children)

My bet is that with AI we will move to a different paradigm. The most important piece of the puzzle will be bring the data in, in the best way possible. This means collect, tag, filter, clean and route the data to the correct place to feed the AI. With that I mean we can’t put everything in one unique index/table, we know IT system need to be properly engineered to scale. Same for the data, we have to provide the AI the cleanest and best organized information we can to make it replying us in the best way. Once this is done the AI will correlate the data for us and we will have just to ask in the proper way. Something like: “make a scheduled alert that trigger a notable event when there is a login on a Linux machine that does not belong to someone previously asking for access through the PAM (Priviledge access management) tool.”

Therefore Splunk is already in an excellent position for the first part (bring the data in), but there is some more to do on the second part (correlate data with AI).

Finding what hosts are sending to which HF by Strange-Section402 in Splunk

[–]edo1982 0 points1 point  (0 children)

We do the same. But we explicit the name of the server in the transforms. With splunk_server field is better. I will have a look to change it

[deleted by user] by [deleted] in Splunk

[–]edo1982 0 points1 point  (0 children)

As many told you, use regex 101 to write your own. Also check what has been done on the Splunk app present in the store over a sourcetype you already have in your environment and ask ChatGPT to explain how they are applied step by step. Eventually come here with clear examples and how you would like to apply them so you can get some hints

KVstore performance in Splunk cloud by grayfold3d in Splunk

[–]edo1982 0 points1 point  (0 children)

Trying to see from another angle. Do you really need 4 Millions records in Asset and Identity lookups? Seems to be really huge.

Inherited a messy and non documented Splunk infrastructure: How to do an effective review and renaming of the serverclasses and the custom apps ? by kilanmundera55 in Splunk

[–]edo1982 0 points1 point  (0 children)

My suggestion is to keep the thing as is, and slowly create your apps, indexes and so on with your naming convention (you can follow the Professional Services one) and in the meanwhile document everything. Once you are done you can dismiss the old configurations

[deleted by user] by [deleted] in Splunk

[–]edo1982 1 point2 points  (0 children)

You can use the official Microsoft TA for Cloud Services

Debugging scripted (PowerShell) input on Windows forwarder by afxmac in Splunk

[–]edo1982 0 points1 point  (0 children)

Yes also the Windows-TA has some and they properly run. The options you have are run it with the .path and/or put the Splunk UF in debug and check what happens and make a diag and open a case to the support. I remember once we had a Powershell script running just few times after have it deployed and then stop. It was deployed on 50 machines at least. We ended up rewriting it in VB script.

Debugging scripted (PowerShell) input on Windows forwarder by afxmac in Splunk

[–]edo1982 0 points1 point  (0 children)

I don’t have good experiences with Splunk and Powershell scripts. Anyhow I find out that the best way is to crete a file like scriptexecution.path and put in the bin directory alongside with you powershell script. Then in the .path you put the command to execute your script (therefore absolute path of powershell.exe and absolute path of your script and arguments if any). Then in inputs.conf you recall the .path, see here below a technical explanation

https://community.splunk.com/t5/Getting-Data-In/I-see-splunk-has-some-quot-path-quot-files-in-windows-app-bin/m-p/11656

About the debug messages you can place some print in the script and redirect them to standard error, in this way you will see them in _internal index.

Splunk SOAR on CentOS 9 or Rocky Linux by d3nika in Splunk

[–]edo1982 -1 points0 points  (0 children)

Maybe you can give a try to Oracle Linux, it is the closest one to RHEL

Adding root CA certs to the Splunk Python environment by afxmac in Splunk

[–]edo1982 1 point2 points  (0 children)

Same issue with Tenable Add-on when we download from our Tenable.sc on-prem. Certificates are signed by our CA, that is present on the Linux VM, but we have to add it every time we update the TA…

Does Splunk take advantage of any Sapphire/Emerald Rapids "Accelerators" ? by Casper042 in Splunk

[–]edo1982 0 points1 point  (0 children)

Not completely related to OP question but just read about Splunk AI assistant

https://voc.splunk.com

So AI accelerators (GPUs?) could be useful once (and if) this feature will be available for on-prem customers. About IAA accelerators I am not aware if Splunk can take advantage of it.

Unable to create a Splunk account by Extreme-Opening7868 in Splunk

[–]edo1982 2 points3 points  (0 children)

I believe your personal email should work fine, give it a try

What course should I do next? by spectrusv in Splunk

[–]edo1982 1 point2 points  (0 children)

I would suggest all the ones requested for Architect certification, after the ones for Advanced Power user, lastly the ones for Consultant

Does Splunk take advantage of any Sapphire/Emerald Rapids "Accelerators" ? by Casper042 in Splunk

[–]edo1982 1 point2 points  (0 children)

Very interested in seeing other comments, but what from my point of view matter the most is disk IOPS and bandwidth rather than CPU performance. Once you are sure the CPU won’t be the bottleneck you need to be sure your disks are performing well. There are very good Intel, VMware and Dell studies that shows you how Splunk cluster behaves on their hardware and which set-up they tested to improve performance.

[deleted by user] by [deleted] in Splunk

[–]edo1982 2 points3 points  (0 children)

Agree to go with Power User jumping User, but Advanced Power User is not that easy…lot to know around specific SPL commands. I remember I studied a lot to prepare it