Find Answers

Find Answers
Ask questions. Get answers. Find technical product solutions from passionate members of the Splunk community.
Category Activity
Ellen
Under Linux Splunk 4.1, I want to install the PDF Report Server and have downloaded the app file from Splunkbase. Whe...
by Ellen Splunk Employee Splunk Employee in Installation 04-08-2010
3 2
3
2
Jaci
In inputs.conf the default host name is set to the fqdn, test-server.foobar.com. But when I search for that host, it ...
by Jaci Splunk Employee Splunk Employee in Getting Data In 04-08-2010
2 5
2
5
rayfoo
Wanted to see what is/are the possible methods to do so. One way I could think of is to export the results using out...
by rayfoo Path Finder in Splunk Search 04-08-2010
1 7
1
7
MHS
I use the following query against a Cisco as5400 to find the number of calls per hour during a day. 10.200.90.19 Cal...
by MHS Explorer in Splunk Search 04-08-2010
0 4
0
4
rnutting24
Hi, I just created a new app and wanted to point my network inputs to another index, managed by my app. So, I modif...
by rnutting24 Engager in Getting Data In 04-08-2010
1 3
1
3
bwooden
On a Solaris machine, I modified $SLUNK_HOME/etc/system/local/web.conf to use httpport = 80 The below error was then ...
by bwooden Splunk Employee Splunk Employee in Security 04-08-2010
4 5
4
5
the_wolverine
Is there a splunk command or REST endpoint to see the tailing status of monitored files?
by the_wolverine Champion in Getting Data In 04-08-2010
4 2
4
2
imrago
After upgrading to 4.1 from 4.0.10 I am unable to get fields using a search from python script. The simplified versio...
by imrago Contributor in Splunk Search 04-08-2010
0 2
0
2
zscgeek
I am trying to get scripted auth working on the new 4.1. I had a configuration on 3.4.x that worked great but after m...
by zscgeek Path Finder in Splunk Search 04-07-2010
0 2
0
2
MikeyG
Search is index="_internal" source="*metrics.log" group="queue" | timechart perc90(current_size) by name Results are...
by MikeyG Explorer in Getting Data In 04-07-2010
2 3
2
3
Mick
I'm trying to index a file on a mapped network drive, but I keep getting seeing 'Access is denied' in splunkd.log. I...
by Mick Splunk Employee Splunk Employee in Getting Data In 04-07-2010
4 1
4
1
Mick
I just upgraded to version 4.1 and I'm seeing this message in the UI. My minimum free disk space is 1GB and I haven'...
by Mick Splunk Employee Splunk Employee in Monitoring Splunk 04-07-2010
2 1
2
1
Justin_Grant
What are the searches required to search across Windows Event Logs for: most recent events of a particular event ID ...
by Justin_Grant Contributor in Splunk Search 04-07-2010
2 1
2
1
the_wolverine
Splunk does such an awesome job with distributed search. It seems like all my data is on one server (my search head)...
by the_wolverine Champion in Splunk Search 04-07-2010
1 2
1
2
rogerssoftware
On my old setup I had all syslogs going to syslog on the Splunk server, but now I'm doing a fresh setup with Ubuntu 9...
by rogerssoftware Explorer in Getting Data In 04-07-2010
1 4
1
4
Alan_Bradley
Splunk is running behind a webserver proxy. Splunk has the following config in web.conf: root_endpoint = /splunk T...
by Alan_Bradley Path Finder in Security 04-07-2010
1 1
1
1
the_wolverine
I have a bunch of Lightweight Forwarders (LWF) forwarding to my central indexer. What happens to my events when the...
by the_wolverine Champion in Getting Data In 04-06-2010
3 4
3
4
Alan_Bradley
I've just upgraded to 4.1 and now I'm getting an error when I search saying: The lookup table 'sid_lookup' does not ...
by Alan_Bradley Path Finder in Getting Data In 04-06-2010
3 7
3
7
cdavidy
How do I go about configuring splunk forwarders running on Linux to forward to a specific index for Linux-related inf...
by cdavidy Explorer in Getting Data In 04-06-2010
5 2
5
2
BunnyHop
When I run a search on my custom dashboard, I get a notification bar on top stating the status of the dashboard queri...
by BunnyHop Contributor in Dashboards & Visualizations 04-06-2010
2 6
2
6
Marinus
I've seen quite a few apps and they structure their file in different ways. Is there a best practice? For example sho...
by Marinus Communicator in All Apps and Add-ons 04-06-2010
2 3
2
3
BunnyHop
If the script to roll the hotDB to the warmDB is "| debug cmd=roll index=main", would there be one for rolling the wa...
by BunnyHop Contributor in Getting Data In 04-06-2010
4 2
4
2
Jack
can I view an entire raw log file from within Splunk? For example, if I'm monitoring an apache log4j file (server.lo...
by Jack Engager in All Apps and Add-ons 04-06-2010
1 3
1
3
zscgeek
Are there are any critical changes to be aware of when migrating a complex distributed scripted auth setup on 3.4.x t...
by zscgeek Path Finder in Deployment Architecture 04-06-2010
1 3
1
3
Alan_Bradley
After upgrading to Splunk 4.1 from 4.0.10 today, we find that we can no longer run searches. splunkd.log shows: 04-...
by Alan_Bradley Path Finder in Splunk Search 04-05-2010
4 1
4
1
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...
Top Karma Authors