Monitoring Splunk

Monitoring Splunk
Community Activity
Jason
A client is looking for advice on tuning splunk for what they call "high performance" - defined as minimizing cpu, ne...
by Jason Motivator in Monitoring Splunk 11-05-2010
0 2
0
2
rvbalaji
Our logfiles are named in the format Log.Activity.prod.###.txt where ### is random number. Also we want to leave out ...
by rvbalaji Explorer in Monitoring Splunk 11-04-2010
0 7
0
7
katalinali
I monitored several thousands of file in splunk but I find it indexes the new events for more than 30 minutes. I have...
by katalinali Path Finder in Monitoring Splunk 11-03-2010
2 1
2
1
standias
Hi, 'Splunk Helpers' what is this process & what does it do? Can it be stopped/started via cmdline. Obviously if cr...
by standias Explorer in Monitoring Splunk 10-26-2010
0 3
0
3
muebel
What configuration needs to be in place in order for internal events from one splunk instance to be in the _internal ...
by SplunkTrust SplunkTrust in Monitoring Splunk 10-22-2010
0 1
0
1
monitor
Splunk seems like an all around tool. What is the advantage of incorporating the Ossec system into or with Splunk?
by monitor New Member in Monitoring Splunk 10-20-2010
0 3
0
3
jhuebner
I've had both services running on the save Ubuntu 10.04 server for about a week. OSSEC is cooking along gathering in...
by jhuebner Explorer in Monitoring Splunk 10-20-2010
0 1
0
1
Dan
I have a 16 core server (HP DL580) with 32GB MEM and 2TB SAS Drives (RAID 10) capable of 800 IO/sec. I'm indexing abo...
by Dan Splunk Employee Splunk Employee in Monitoring Splunk 10-19-2010
1 6
1
6
Marcin
I keep getting the following error in crash logs on splunk-3.4.12-69236 64 bit. Anyone has any idea what is causing i...
by Marcin Explorer in Monitoring Splunk 10-08-2010
0 1
0
1
gmor
Hi Folks, I could use some pointers troubleshooting some Splunk Web performance issues. Over the last few weeks, ou...
by gmor Explorer in Monitoring Splunk 09-23-2010
1 3
1
3
atulmistry
we have a license for our QA environment for 500MB. We wanted to have the same functions (deployment, alerts, securit...
by atulmistry Engager in Monitoring Splunk 09-20-2010
4 2
4
2
mctester
When I try to start Splunk it gives the following output - Splunk> CSI: Logfiles. Checking prerequisites... Chec...
by mctester Communicator in Monitoring Splunk 09-17-2010
4 4
4
4
sfmandmdev
How do I force splunk to index new files in the directory that is being monitored immediately? sometimes it takes rea...
by sfmandmdev Path Finder in Monitoring Splunk 09-13-2010
1 1
1
1
mzorzi
I can see the maxfiles parameter in $SPLUNK_HOME/etc/system/default/limits.conf for Splunk 4.1.4 , but it is not desc...
by mzorzi Splunk Employee Splunk Employee in Monitoring Splunk 09-10-2010
2 1
2
1
Lowell
Is there a way to explicitly set the reduce_freq for a given saved search? I don't see a dispatch.* option for this ...
by Lowell Super Champion in Monitoring Splunk 09-07-2010
1 1
1
1
Jason
I'm working on a box right now that seems to be unnecessarily slow at both searching as well as indexing from a batch...
by Jason Motivator in Monitoring Splunk 09-07-2010
0 5
0
5
mctester
We created a new index called "foo"; its size is about 6.6GB on disk. Our main index "main" is 66GB. Our daily index...
by mctester Communicator in Monitoring Splunk 09-01-2010
0 1
0
1
tier2ops
I have a search that is taking a few days to run. Here is the search string: sourcetype="bcoat_proxysg" | stats dc(...
by tier2ops Explorer in Monitoring Splunk 08-25-2010
0 3
0
3
dcarlo
I have a Solaris 10 SPARC server that is running Splunk 4.1. It's configured to generate audit logs to syslog, creat...
by dcarlo New Member in Monitoring Splunk 08-22-2010
0 1
0
1
rroberts
What is the significance of cumulative_hits below? Search match hits? number of events returned from a search? 07-09...
by rroberts Splunk Employee Splunk Employee in Monitoring Splunk 08-17-2010
1 3
1
3
roguerr
Crash results in corrupt metadata preventing Splunk from starting up again. Look for following line before crash in s...
by roguerr Engager in Monitoring Splunk 08-09-2010
1 2
1
2
MJTrigwell
Hi, I am having problems getting Splunk to monitor WebSphere V7. I have enabled PMI on WebSphere and installed Splu...
by MJTrigwell Engager in Monitoring Splunk 08-03-2010
2 4
2
4
Michael_Wilde
I've just setup a search head that will search across 2 load balanced indexers.  I'd like to compare the execution ti...
by Michael_Wilde Splunk Employee Splunk Employee in Monitoring Splunk 07-21-2010
1 1
1
1
skippylou
So if I follow the data space and retirement process correctly, it works in a circular manner with old data being del...
by skippylou Communicator in Monitoring Splunk 07-20-2010
1 2
1
2
Lowell
I just upgraded one of my splunk forwarders to version 4.1.4 and now I'm seeing the following error message in my int...
by Lowell Super Champion in Monitoring Splunk 07-20-2010
2 1
2
1
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...