Find Answers

Find Answers
Ask questions. Get answers. Find technical product solutions from passionate members of the Splunk community.
Category Activity
Marinus
I've seen quite a few apps and they structure their file in different ways. Is there a best practice? For example sho...
by Marinus Communicator in All Apps and Add-ons 04-06-2010
2 3
2
3
BunnyHop
If the script to roll the hotDB to the warmDB is "| debug cmd=roll index=main", would there be one for rolling the wa...
by BunnyHop Contributor in Getting Data In 04-06-2010
4 2
4
2
Jack
can I view an entire raw log file from within Splunk? For example, if I'm monitoring an apache log4j file (server.lo...
by Jack Engager in All Apps and Add-ons 04-06-2010
1 3
1
3
zscgeek
Are there are any critical changes to be aware of when migrating a complex distributed scripted auth setup on 3.4.x t...
by zscgeek Path Finder in Deployment Architecture 04-06-2010
1 3
1
3
Alan_Bradley
After upgrading to Splunk 4.1 from 4.0.10 today, we find that we can no longer run searches. splunkd.log shows: 04-...
by Alan_Bradley Path Finder in Splunk Search 04-05-2010
4 1
4
1
SteveS
If I have a bunch of saved searches I run hourly, what should I consider before switching any or all of them to real ...
by SteveS Splunk Employee Splunk Employee in Splunk Search 04-05-2010
2 2
2
2
thepocketwade
In my office we have a script on our log servers that monitors the hosts sending logs and alerts us if a machine star...
by thepocketwade Path Finder in Getting Data In 04-05-2010
0 4
0
4
oreoshake
I'm in the process of migrating to new hardware for my indexers. The easiest way to do this would be: Setup new ind...
by oreoshake Communicator in Installation 04-05-2010
2 3
2
3
Alan_Bradley
I just upgraded from 4.0 to 4.1 and am seeing messages that the indexprocessor was not initialized on startup. How c...
by Alan_Bradley Path Finder in Installation 04-05-2010
2 1
2
1
Justin_Grant
How many tags can be created before Splunk's performance is adversely affected? And what specifcally is adversely af...
by Justin_Grant Contributor in Monitoring Splunk 04-05-2010
3 4
3
4
mfrost8
I'm using Splunk 4.0.10. I've been working on doing field extractions (transforms.conf) on a DB2 log file. I've man...
by mfrost8 Builder in Splunk Search 04-05-2010
0 1
0
1
zscgeek
Question: What pipeline module does the sed pre-indexing code run in. I have the following props.conf in my app an...
by zscgeek Path Finder in Splunk Search 04-05-2010
1 1
1
1
oreoshake
All of my events show up with gid=-1,uid=-1. Is this a bug or am I doing something wrong?
by oreoshake Communicator in Getting Data In 04-05-2010
1 3
1
3
Simeon
I have a lot of saved searches that populate my summary index and I do not want them to be viewable in the saved sear...
by Simeon Splunk Employee Splunk Employee in Reporting 04-05-2010
5 3
5
3
the_wolverine
I'm trying to set up LDAP authentication and need some assistance. Where do I go for assistance?
by the_wolverine Champion in Security 04-05-2010
2 1
2
1
oreoshake
Any idea how to create a search that finds hosts that are sending BOTH syslog and splunkd traffic? We'd like to turn...
by oreoshake Communicator in Installation 04-05-2010
1 2
1
2
oreoshake
When uninstalling an app, the following errors are preventing splunkd for restarting: 03-30-2010 22:28:12.157 WARN ...
by oreoshake Communicator in Deployment Architecture 04-04-2010
1 2
1
2
Lowell
How do you force the creation of the merged_lexicon.lex for a bucket that was manually restored? (And is this possib...
by Lowell Super Champion in Deployment Architecture 04-03-2010
0 4
0
4
oreoshake
UPDATE: This appears to be a bug specifically related to 4.0.10. The following is a work around in system/local/inp...
by oreoshake Communicator in Getting Data In 04-03-2010
1 3
1
3
the_wolverine
I need some help with figuring out some potential blocked queues. What searches can be run to help me figure this ou...
by the_wolverine Champion in Monitoring Splunk 04-02-2010
0 2
0
2
Chris_R_
My filesystem is full and splunk wont start. How do i make some last minute filesystem space and start splunk? What a...
by Chris_R_ Splunk Employee Splunk Employee in Deployment Architecture 04-02-2010
3 2
3
2
Jaci
Saw this error in splunklogger.log. What does it mean?
by Jaci Splunk Employee Splunk Employee in Splunk Search 04-01-2010
1 1
1
1
rsimmons
We are indexing a lot of Cisco syslog messages. I notice that the host field is extracted correctly, but src/dst IP a...
by rsimmons Splunk Employee Splunk Employee in Splunk Search 04-01-2010
3 3
3
3
Peter
I have a script that populates the previous day's data early in the following morning. How do I set a time range such...
by Peter Path Finder in Splunk Search 04-01-2010
2 3
2
3
thepocketwade
I've got a field extraction defined in my props.conf, but now I want to be able to select it in a search without usin...
by thepocketwade Path Finder in Splunk Search 04-01-2010
1 5
1
5
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...
Top Karma Authors