Saved Bookmarks
| 1. |
Explain how Splunk avoids duplicate indexing of logs. |
|
Answer» Essentially, Splunk Fishbucket is a subdirectory within Splunk that is USED to MONITOR and track the extent to which the content of a file has been indexed within Splunk. The default location of the fish bucket subdirectory is: /opt/splunk/var/lib/splunk It generally INCLUDES SEEKING pointers and CRCs (cyclic redundancy checks) for the FILES we are indexing so that Splunk knows whether it has already read them. |
|