1: 背景:
最近客户的Splunk UBA 的单节点,要接入的datasource 比较多,而且数据量还比较大,所以还是考虑要部署cluster, 下面参考:
Install Splunk UBA on several VMware virtual machines - Splunk Documentation
按照步骤一步一步来,是可以的,但是我发现配的时候,报zoopkeeper 的报错,说 :
Force enabled, data/txnlog directories will be re-initialized
No myid provided, be sure to specify it in /var/lib/zookeeper/data/myid if using non-standalone
1
Job for zookeeper-server.service failed because a configured resource limit was exceeded. See "systemctl status zookeeper-server.service" and "journalctl -xe" for details.
Failed to run sudo service zookeeper-server start