Monitoring Splunk

Monitoring Splunk
Community Activity
katalinali
I write a script to blacklist the oldest file but splunk don't reload inputs.conf until someone restart the services ...
by katalinali Path Finder in Monitoring Splunk 11-08-2010
0 3
0
3
Jason
A client is looking for advice on tuning splunk for what they call "high performance" - defined as minimizing cpu, ne...
by Jason Motivator in Monitoring Splunk 11-05-2010
0 2
0
2
rvbalaji
Our logfiles are named in the format Log.Activity.prod.###.txt where ### is random number. Also we want to leave out ...
by rvbalaji Explorer in Monitoring Splunk 11-04-2010
0 7
0
7
katalinali
I monitored several thousands of file in splunk but I find it indexes the new events for more than 30 minutes. I have...
by katalinali Path Finder in Monitoring Splunk 11-03-2010
2 1
2
1
standias
Hi, 'Splunk Helpers' what is this process & what does it do? Can it be stopped/started via cmdline. Obviously if cr...
by standias Explorer in Monitoring Splunk 10-26-2010
0 3
0
3
muebel
What configuration needs to be in place in order for internal events from one splunk instance to be in the _internal ...
by SplunkTrust SplunkTrust in Monitoring Splunk 10-22-2010
0 1
0
1
monitor
Splunk seems like an all around tool. What is the advantage of incorporating the Ossec system into or with Splunk?
by monitor New Member in Monitoring Splunk 10-20-2010
0 3
0
3
jhuebner
I've had both services running on the save Ubuntu 10.04 server for about a week. OSSEC is cooking along gathering in...
by jhuebner Explorer in Monitoring Splunk 10-20-2010
0 1
0
1
Dan
I have a 16 core server (HP DL580) with 32GB MEM and 2TB SAS Drives (RAID 10) capable of 800 IO/sec. I'm indexing abo...
by Dan Splunk Employee Splunk Employee in Monitoring Splunk 10-19-2010
1 6
1
6
Marcin
I keep getting the following error in crash logs on splunk-3.4.12-69236 64 bit. Anyone has any idea what is causing i...
by Marcin Explorer in Monitoring Splunk 10-08-2010
0 1
0
1
gmor
Hi Folks, I could use some pointers troubleshooting some Splunk Web performance issues. Over the last few weeks, ou...
by gmor Explorer in Monitoring Splunk 09-23-2010
1 3
1
3
atulmistry
we have a license for our QA environment for 500MB. We wanted to have the same functions (deployment, alerts, securit...
by atulmistry Engager in Monitoring Splunk 09-20-2010
4 2
4
2
mctester
When I try to start Splunk it gives the following output - Splunk> CSI: Logfiles. Checking prerequisites... Chec...
by mctester Communicator in Monitoring Splunk 09-17-2010
4 4
4
4
sfmandmdev
How do I force splunk to index new files in the directory that is being monitored immediately? sometimes it takes rea...
by sfmandmdev Path Finder in Monitoring Splunk 09-13-2010
1 1
1
1
mzorzi
I can see the maxfiles parameter in $SPLUNK_HOME/etc/system/default/limits.conf for Splunk 4.1.4 , but it is not desc...
by mzorzi Splunk Employee Splunk Employee in Monitoring Splunk 09-10-2010
2 1
2
1
Lowell
Is there a way to explicitly set the reduce_freq for a given saved search? I don't see a dispatch.* option for this ...
by Lowell Super Champion in Monitoring Splunk 09-07-2010
1 1
1
1
Jason
I'm working on a box right now that seems to be unnecessarily slow at both searching as well as indexing from a batch...
by Jason Motivator in Monitoring Splunk 09-07-2010
0 5
0
5
mctester
We created a new index called "foo"; its size is about 6.6GB on disk. Our main index "main" is 66GB. Our daily index...
by mctester Communicator in Monitoring Splunk 09-01-2010
0 1
0
1
tier2ops
I have a search that is taking a few days to run. Here is the search string: sourcetype="bcoat_proxysg" | stats dc(...
by tier2ops Explorer in Monitoring Splunk 08-25-2010
0 3
0
3
dcarlo
I have a Solaris 10 SPARC server that is running Splunk 4.1. It's configured to generate audit logs to syslog, creat...
by dcarlo New Member in Monitoring Splunk 08-22-2010
0 1
0
1
rroberts
What is the significance of cumulative_hits below? Search match hits? number of events returned from a search? 07-09...
by rroberts Splunk Employee Splunk Employee in Monitoring Splunk 08-17-2010
1 3
1
3
roguerr
Crash results in corrupt metadata preventing Splunk from starting up again. Look for following line before crash in s...
by roguerr Engager in Monitoring Splunk 08-09-2010
1 2
1
2
MJTrigwell
Hi, I am having problems getting Splunk to monitor WebSphere V7. I have enabled PMI on WebSphere and installed Splu...
by MJTrigwell Engager in Monitoring Splunk 08-03-2010
2 4
2
4
Michael_Wilde
I've just setup a search head that will search across 2 load balanced indexers.  I'd like to compare the execution ti...
by Michael_Wilde Splunk Employee Splunk Employee in Monitoring Splunk 07-21-2010
1 1
1
1
skippylou
So if I follow the data space and retirement process correctly, it works in a circular manner with old data being del...
by skippylou Communicator in Monitoring Splunk 07-20-2010
1 2
1
2
Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...