| Thread Info | |||||
|---|---|---|---|---|---|
| 
        A client asks: is there any performance improvement by having multiple indexes? 
  I'm guessing that there would be, ...
        
         
           by 
           
                
                    
                        Jason
                    
                
           
             
             
               Motivator
             
           
           in
           Monitoring Splunk
           
           
              
               06-22-2010
             
           
         
        | 
		
		1
   | 
	  
	  2
	 | |||
| 
        is there a way to track configuration changes to splunk - either via splunkweb or command line? The idea is: Lets say...
        
         
           by 
           
                
                    
                        Genti
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Monitoring Splunk
           
           
              
               06-01-2010
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Hi all, 
  I've been searching high and low to understand how to get Splunk aware of the changes in inputs.conf of an...
        
         
           by 
           
                
                    
                        Nicholas_Key
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Monitoring Splunk
           
           
              
               06-03-2010
             
           
         
        | 
		
		2
   | 
	  
	  3
	 | |||
| 
        I'm looking on the "Overview" (scheduler_status) view in the Splunk 4.1 Search app and I'm trying to understand what ...
        
         
           by 
           
                
                    
                        Lowell
                    
                
           
             
             
               Super Champion
             
           
           in
           Monitoring Splunk
           
           
              
               05-26-2010
             
           
         
        | 
		
		1
   | 
	  
	  3
	 | |||
| 
        I'm currently working with inputs.conf and would like to have the stanzas recognize the values that are assigned to t...
        
         
           by 
           
                
                    
                        Nicholas_Key
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Monitoring Splunk
           
           
              
               04-30-2010
             
           
         
        | 
		
		3
   | 
	  
	  5
	 | |||
| 
        Is the output of 'splunk list monitor' clipped at all?  
  I have a directory with (approx) 50 log files, but the out...
        
         
           by 
           
                
                    
                        dwaddle
                    
                
           
             
             
               SplunkTrust
             
           
           in
           Monitoring Splunk
           
           
              
               05-25-2010
             
           
         
        | 
		
		3
   | 
	  
	  4
	 | |||
| 
        I want to use Splunk to monitor the error output of a telephone switch. I can easily see the data by connecting to th...
        
         
           by 
           
                
                    
                        johnpulley
                    
                
           
             
             
               New Member
             
           
           in
           Monitoring Splunk
           
           
              
               05-21-2010
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Hi, 
  Been trying to backup and restore of Splunk indexer and the steps that I took to backup our splunk server is:
...
        
         
           by 
           
                
                    
                        apro
                    
                
           
             
             
               Path Finder
             
           
           in
           Monitoring Splunk
           
           
              
               05-21-2010
             
           
         
        | 
		
		1
   | 
	  
	  2
	 | |||
| 
        The following line is found when I try to restart the stopped splunkd process:- 
  05-12-2010 14:30:50.819 ERROR Word...
        
         
           by 
           
                
                    
                        aiwatson
                    
                
           
             
             
               Engager
             
           
           in
           Monitoring Splunk
           
           
              
               05-12-2010
             
           
         
        | 
		
		2
   | 
	  
	  1
	 | |||
| 
        Is there anyway to run an sql like 'plan' on a splunk search to determine efficiency?
        
         
           by 
           
                
                    
                        bfaber
                    
                
           
             
             
               Communicator
             
           
           in
           Monitoring Splunk
           
           
              
               04-29-2010
             
           
         
        | 
		
		5
   | 
	  
	  4
	 | |||
| 
        When I queried a new Summary Index with only 100k of events and 16MB of size, the response time of the a simple query...
        
         
           by 
           
                
                    
                        Mick
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Monitoring Splunk
           
           
              
               02-08-2010
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hello 
  How can I monitor the files within a directory but ignore its subdirectories? 
  e.g. I want to monitor all ...
        
         
           by 
           
                
                    
                        Josh
                    
                
           
             
             
               Path Finder
             
           
           in
           Monitoring Splunk
           
           
              
               04-16-2010
             
           
         
        | 
		
		2
   | 
	  
	  2
	 | |||
| 
        I just upgraded to version 4.1 and I'm seeing this message in the UI. My minimum free disk space is 1GB and I haven't...
        
         
           by 
           
                
                    
                        Mick
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Monitoring Splunk
           
           
              
               04-07-2010
             
           
         
        | 
		
		2
   | 
	  
	  1
	 | |||
| 
        How many tags can be created before Splunk's performance is adversely affected? And what specifcally is adversely aff...
        
         
           by 
           
                
                    
                        Justin_Grant
                    
                
           
             
             
               Contributor
             
           
           in
           Monitoring Splunk
           
           
              
               01-22-2010
             
           
         
        | 
		
		3
   | 
	  
	  4
	 | |||
| 
        I need some help with figuring out some potential blocked queues. What searches can be run to help me figure this out...
        
         
           by 
           
                
                    
                        the_wolverine
                    
                
           
             
             
               Champion
             
           
           in
           Monitoring Splunk
           
           
              
               03-30-2010
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Some of our servers are running low on Disk capacity and we are concerned with splunk log files generated and stored ...
        
         
           by 
           
                
                    
                        Mick
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Monitoring Splunk
           
           
              
               03-30-2010
             
           
         
        | 
		
		7
   | 
	  
	  2
	 | |||
| 
        We have Splunk as part of our default vm image but we're having some bucket issues. Initially, the time isn't set and...
        
         
           by 
           
                
                    
                        oreoshake
                    
                
           
             
             
               Communicator
             
           
           in
           Monitoring Splunk
           
           
              
               03-17-2010
             
           
         
        | 
		
		2
   | 
	  
	  1
	 | |||
| 
        I notice there is support for fifo's as inputs. Are there any benefits to using a fifo or is it just support for thos...
        
         
           by 
           
                
                    
                        Erik_Swan
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Monitoring Splunk
           
           
              
               02-13-2010
             
           
         
        | 
		
		1
   | 
	  
	  2
	 | |||
| 
        I've followed the instructions on http://www.splunk.com/base/Documentation/4.0.9/Developer/DefaultApp to set the defa...
        
         
           by 
           
                
                    
                        oreoshake
                    
                
           
             
             
               Communicator
             
           
           in
           Monitoring Splunk
           
           
              
               03-10-2010
             
           
         
        | 
		
		6
   | 
	  
	  2
	 | |||
| 
        I looked at the report for timestamping errors and found a fair amount of errors. I’ve been following the Splunk blog...
        
         
           by 
           
                
                    
                        oreoshake
                    
                
           
             
             
               Communicator
             
           
           in
           Monitoring Splunk
           
           
              
               03-09-2010
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Seeing this error in splunkd.log on a splunk indexer when running a saved search. What does it mean?
        
         
           by 
           
                
                    
                        Jaci
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Monitoring Splunk
           
           
              
               02-26-2010
             
           
         
        | 
		
		2
   | 
	  
	  1
	 | |||
| 
        I'm thinking about using the DEDUP commend to solve the following problem: I have an event with an ID field and I'd l...
        
         
           by 
           
                
                    
                        Justin_Grant
                    
                
           
             
             
               Contributor
             
           
           in
           Monitoring Splunk
           
           
              
               01-22-2010
             
           
         
        | 
		
		2
   | 
	  
	  1
	 | |||
| 
        I will have 100GB coming in per day, with an expectation of 20 concurrent users at any given time, with probably arou...
        
         
           by 
           
                
                    
                        jrodman
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Monitoring Splunk
           
           
              
               01-20-2010
             
           
         
        | 
		
		2
   | 
	  
	  1
	 |