Monitoring Splunk

Monitoring Splunk
Community Activity
jszyba
Is there any way to have a forwarder process not constantly running but rather start up every x hours or so? I'm tryi...
by jszyba New Member in Monitoring Splunk 03-19-2014
0 5
0
5
jszyba
Could anybody tell me how to work with the inputs.conf file of a forwarder to set the forwarder to start/stop/index e...
by jszyba New Member in Monitoring Splunk 03-19-2014
0 1
0
1
jszyba
I have 3 servers each with a log file. I am planning on installing a universal forwarder on each server to push the i...
by jszyba New Member in Monitoring Splunk 03-17-2014
0 3
0
3
sharat_cwc
Hi, I would like to know if Splunk will fetch results from source files that are removed either from their location o...
by sharat_cwc New Member in Monitoring Splunk 03-14-2014
0 1
0
1
steveirogers
Is there a version of this app that is compatible with Splunk version 6?
by steveirogers Communicator in Monitoring Splunk 03-12-2014
0 3
0
3
bruceclarke
All, We are having an issue where one of our Splunk indexers is crashing occasionally. The error we see in the log f...
by bruceclarke Contributor in Monitoring Splunk 03-11-2014
1 3
1
3
sgarvin55
Several times of the past few weeks we have tried to log into Splunk and have been greeted by a 500 Internal Server E...
by sgarvin55 Splunk Employee Splunk Employee in Monitoring Splunk 03-10-2014
2 6
2
6
kmsnyde
I cannot create a dashboard panel. I am using Splunk 5.0.1. After running a saved search and getting the results, I...
by kmsnyde Explorer in Monitoring Splunk 03-10-2014
0 4
0
4
somesoni2
Hi All, I have a lookup file which changes frequently. Currently, we are have a base csv file physically on the serv...
by Revered Legend in Monitoring Splunk 03-06-2014
1 8
1
8
michael_peters
I have just installed Splunk 6.0.2 on Mac OS X 10.7.5 and am getting the following error when starting splunk: bash-...
by michael_peters Path Finder in Monitoring Splunk 03-06-2014
0 2
0
2
FritzWittwer_ol
Old Sparc HW, specially the T1,T2 and T4 CPUs is known to be not well suited for Splunk as it has a rather poor singl...
by FritzWittwer_ol Contributor in Monitoring Splunk 03-04-2014
0 1
0
1
Lowell
Any suggestions on techniques (or KPIs) for trending realtime searches within a Splunk environment? I'm doing some s...
by Lowell Super Champion in Monitoring Splunk 02-28-2014
1 2
1
2
strive
Hi, We use splunk 5.0.4. We have customers with daily log volume ranging from 10GB to 50GB. Our customers do not wa...
by strive Influencer in Monitoring Splunk 02-22-2014
0 10
0
10
ionitsupport
Can't get this working with Splunk for Cisco ASA Set ASA 5505 to forward syslog to usp/5447 with timestamps enabled ...
by ionitsupport New Member in Monitoring Splunk 02-13-2014
0 3
0
3
juniormint
I would like to generate a plot of cpu utilization over time. I have some permon events coming in that look like 02...
by juniormint Communicator in Monitoring Splunk 02-11-2014
0 1
0
1
edenzler
Error in 'databasePartitionPolicy': Failed to read 1 event(s) from rawdata in bucket '_internal~235~8AD95516-6DE5-4CC...
by edenzler Path Finder in Monitoring Splunk 02-11-2014
0 2
0
2
MarMoh
Hi All, Currently we are running a stand alone Enterprise version of Splunk(500M/day) on a Windows server. Since Our...
by MarMoh Path Finder in Monitoring Splunk 02-11-2014
0 4
0
4
helge
I am executing the following command on a Windows Server 2012 R2 machine with Splunk 6.0.1: C:\Program Files\Splunk\...
by helge Builder in Monitoring Splunk 02-10-2014
2 4
2
4
kishorecsit
0
2
brianma
Hello, I have DL'd and installed the following: Splunk App for Cisco ASA ver 1.0 Splunk for Cisco ASA Technology Ad...
by brianma New Member in Monitoring Splunk 01-29-2014
0 2
0
2
rupesh212121
hi i am getting an error in splunk as soon as i login the error is "skipped indexing of internal audit event will kee...
by rupesh212121 Explorer in Monitoring Splunk 01-23-2014
2 2
2
2
apringle
I just added a new Universal Forwarder to our Splunk deployment (we previously were running everything on a single se...
by apringle Explorer in Monitoring Splunk 01-22-2014
3 7
3
7
woodcock
I am out of disk space on my oldest search head because of this: cd ${SPLUNK_HOME}/var/lib/splunk; du -sh ./* 2> /de...
by Esteemed Legend in Monitoring Splunk 01-22-2014
0 4
0
4
MegSplunk
I have a summary search. I get errors. I need to know how much memory my search consumes. How do I achieve that? ...
by MegSplunk Path Finder in Monitoring Splunk 01-16-2014
0 2
0
2
daktapaal
Hi all, I wanted to know the behavior of *. When I do index = *, does it get me all the indexes? I have the follow...
by daktapaal Path Finder in Monitoring Splunk 01-14-2014
0 2
0
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...
Top Solution Authors