1.

Explain how Splunk avoids duplicate indexing of logs.

Answer»

Essentially, Splunk Fishbucket is a subdirectory within Splunk that is USED to MONITOR and track the extent to which the content of a file has been indexed within Splunk. 

The default location of the fish bucket subdirectory is: /opt/splunk/var/lib/splunk

It generally INCLUDES SEEKING pointers and CRCs (cyclic redundancy checks) for the FILES we are indexing so that Splunk knows whether it has already read them. 



Discussion

No Comment Found