Monitoring Splunk

Monitoring Splunk
Community Activity
xiaotao
Hiya Thinking of using Splunk but worry Splunk takes too much PC resources if use it directly on the servers where t...
by xiaotao New Member in Monitoring Splunk 01-14-2011
0 1
0
1
hochit
I know I can monitor the usage of saved search by saved_search_name from _audit index. However, I can't find equivale...
by hochit Path Finder in Monitoring Splunk 12-30-2010
1 1
1
1
vadud3
11-09-2010 00:00:57.985 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire...
by vadud3 Path Finder in Monitoring Splunk 12-24-2010
1 1
1
1
melonman
Hi, I want to use google analytics to get user trace. In which template should I put the google analytics code so th...
by melonman Motivator in Monitoring Splunk 12-16-2010
0 1
0
1
domengph
Is it possible to explicitly define how much memory splunk (splunkd and splunkweb) is allowed to use? Thanks
by domengph Engager in Monitoring Splunk 12-10-2010
1 4
1
4
spowell
Hello, It looks like I'm running out of space on my splunk server. Here is the error that I received when running a...
by spowell New Member in Monitoring Splunk 12-08-2010
0 1
0
1
DrewO
Is there a performance difference between using the SEDCMD syntax in just props.conf versus using the older method wh...
by DrewO Splunk Employee Splunk Employee in Monitoring Splunk 12-02-2010
3 3
3
3
Branden
We're considering moving our Splunk environment from AIX to a Linux x86 box for performance reasons. My particular de...
by Branden Builder in Monitoring Splunk 12-01-2010
0 3
0
3
gfriedmann
Has anyone used an ioDrive for their splunk? I'm really curious if anyone can speak to the crazy high IOPS & throughp...
by gfriedmann Communicator in Monitoring Splunk 11-26-2010
3 2
3
2
southeringtonp
Does Splunk make full use of operating system specific features when monitoring for changed files? In particular, I'...
by southeringtonp Motivator in Monitoring Splunk 11-11-2010
1 1
1
1
dwaddle
When you specify a coldToFrozenScript in indexes.conf, what is responsible for deleting the cold bucket from the inde...
by SplunkTrust SplunkTrust in Monitoring Splunk 11-10-2010
2 1
2
1
mgherman
Hi, In an attempt to increase the available storage for indexes, I am looking at moving the colddb indexes to an add...
by mgherman Explorer in Monitoring Splunk 11-08-2010
3 2
3
2
katalinali
I write a script to blacklist the oldest file but splunk don't reload inputs.conf until someone restart the services ...
by katalinali Path Finder in Monitoring Splunk 11-08-2010
0 3
0
3
Jason
A client is looking for advice on tuning splunk for what they call "high performance" - defined as minimizing cpu, ne...
by Jason Motivator in Monitoring Splunk 11-05-2010
0 2
0
2
rvbalaji
Our logfiles are named in the format Log.Activity.prod.###.txt where ### is random number. Also we want to leave out ...
by rvbalaji Explorer in Monitoring Splunk 11-04-2010
0 7
0
7
katalinali
I monitored several thousands of file in splunk but I find it indexes the new events for more than 30 minutes. I have...
by katalinali Path Finder in Monitoring Splunk 11-03-2010
2 1
2
1
standias
Hi, 'Splunk Helpers' what is this process & what does it do? Can it be stopped/started via cmdline. Obviously if cr...
by standias Explorer in Monitoring Splunk 10-26-2010
0 3
0
3
muebel
What configuration needs to be in place in order for internal events from one splunk instance to be in the _internal ...
by SplunkTrust SplunkTrust in Monitoring Splunk 10-22-2010
0 1
0
1
monitor
Splunk seems like an all around tool. What is the advantage of incorporating the Ossec system into or with Splunk?
by monitor New Member in Monitoring Splunk 10-20-2010
0 3
0
3
jhuebner
I've had both services running on the save Ubuntu 10.04 server for about a week. OSSEC is cooking along gathering in...
by jhuebner Explorer in Monitoring Splunk 10-20-2010
0 1
0
1
Dan
I have a 16 core server (HP DL580) with 32GB MEM and 2TB SAS Drives (RAID 10) capable of 800 IO/sec. I'm indexing abo...
by Dan Splunk Employee Splunk Employee in Monitoring Splunk 10-19-2010
1 6
1
6
Marcin
I keep getting the following error in crash logs on splunk-3.4.12-69236 64 bit. Anyone has any idea what is causing i...
by Marcin Explorer in Monitoring Splunk 10-08-2010
0 1
0
1
gmor
Hi Folks, I could use some pointers troubleshooting some Splunk Web performance issues. Over the last few weeks, ou...
by gmor Explorer in Monitoring Splunk 09-23-2010
1 3
1
3
atulmistry
we have a license for our QA environment for 500MB. We wanted to have the same functions (deployment, alerts, securit...
by atulmistry Engager in Monitoring Splunk 09-20-2010
4 2
4
2
mctester
When I try to start Splunk it gives the following output - Splunk> CSI: Logfiles. Checking prerequisites... Chec...
by mctester Communicator in Monitoring Splunk 09-17-2010
4 4
4
4
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...
Top Solution Authors