Monitoring Splunk

Monitoring Splunk
Community Activity
jonathan_cooper
Trying to figure out what these crash logs mean, I get some every minute, sometimes multiple times: [build 149561] ...
by jonathan_cooper Communicator in Monitoring Splunk 08-07-2013
1 5
1
5
the_wolverine
I'm seeing the following entry every minute in audit.log: Audit:[timestamp=08-05-2013 18:10:09.376, user=admin, acti...
by the_wolverine Champion in Monitoring Splunk 08-05-2013
0 1
0
1
hartfoml
I have this search to find disk space use over time; `index="os" sourcetype="df" host=All_My_Servers | multikv field...
by hartfoml Motivator in Monitoring Splunk 08-05-2013
0 3
0
3
Strype
I had two large apps causing my knowledge bundle to time out. I deleted both app folders in etc apps and in etc user ...
by Strype Path Finder in Monitoring Splunk 08-01-2013
0 4
0
4
Branden
Let me preface this question by stating that we currently do not have any major performance issues at this time. Ou...
by Branden Builder in Monitoring Splunk 08-01-2013
1 6
1
6
mookiie2005
We have around 80 saved searches that run per minute on our search head. Each night we see the search dispatch times...
by mookiie2005 Communicator in Monitoring Splunk 07-31-2013
1 12
1
12
t9445
Hi, hoping this is a basic question, the lead-in is long, however the questions are brief. We have Multiple Data-Cen...
by t9445 Path Finder in Monitoring Splunk 07-31-2013
0 2
0
2
danielrusso1
How does Splunk determine which events to scan in order to find results? For example, say I run a query to find a pa...
by danielrusso1 Path Finder in Monitoring Splunk 07-30-2013
0 3
0
3
the_wolverine
I'd like to set a custom banner to notify users of outages, for example, a single indexer is down and OPS is working ...
by the_wolverine Champion in Monitoring Splunk 07-30-2013
2 2
2
2
muthukrishnan
I seen several file is shown .tsidx under the C:\Program Files\Splunk folder. I want to know how to open that file.
by muthukrishnan New Member in Monitoring Splunk 07-25-2013
0 5
0
5
aholzer
We had a working installation of the Splunk DB Connect app until Friday. While no changes were made to the configura...
by aholzer Motivator in Monitoring Splunk 07-25-2013
2 11
2
11
behymejt2012
Hi Everyone, Looks for a few best practices or suggestions. I have installed search term restrictions based on a use...
by behymejt2012 Path Finder in Monitoring Splunk 07-25-2013
1 2
1
2
binuj
I am trying splunk and wanted to see the URL monitoring using Webmon. I have installed Webmon and added the following...
by binuj Explorer in Monitoring Splunk 07-21-2013
2 17
2
17
Lowell
I started seeing the following message at the top of the Splunk Web page after installing the Deployment Monitor app....
by Lowell Super Champion in Monitoring Splunk 07-18-2013
4 1
4
1
bcarlson
Good Afternoon! I am trying to create a report that goes through a 15 Million record file and creates a cost of roam...
by bcarlson New Member in Monitoring Splunk 07-16-2013
0 10
0
10
benjiw
Greetings all, We have a smallish amount of enterprise licenses, in one stack, most of this is in one larger (produc...
by benjiw Explorer in Monitoring Splunk 07-15-2013
1 5
1
5
grijhwani
Using the following search, I find that in the hour after midnight there is a spike in indexing activity: index="_in...
by grijhwani Motivator in Monitoring Splunk 07-11-2013
0 3
0
3
avitallange
Hi, I have the following folder structure: C:\temp\logs\ComponentName1\InstanceName1\log.txt C:\temp\logs\ComponentN...
by avitallange Explorer in Monitoring Splunk 07-10-2013
0 3
0
3
motobeats
We have an extensive Sitescope implementation and would like to use Splunk to display the status of the various monit...
by motobeats Path Finder in Monitoring Splunk 07-09-2013
0 4
0
4
drussell88
I am having an issue with lag time in my scheduled searches of time. I am looking for all time of issues that may sl...
by drussell88 Explorer in Monitoring Splunk 07-08-2013
0 5
0
5
jakubincloud
Hello, I have an environment with 2 search heads and 2 indexers. There are 70ish forwarders which send around 50 MB...
by jakubincloud Explorer in Monitoring Splunk 07-06-2013
0 3
0
3
rettops
What determines the performance of loading the artifacts of a savedsearch? I have a job which ran a savedsearch, and...
by rettops Path Finder in Monitoring Splunk 07-01-2013
1 1
1
1
YisroelB
It looks as if btool, when run with --debug, only shows the first 10 characters of the app name. Unfortunately the f...
by YisroelB Explorer in Monitoring Splunk 06-28-2013
1 6
1
6
responsys_cm
Prior to the 5.x (and possibly earlier), Splunk logged user searches from the GUI in a human readable format. The ev...
by responsys_cm Builder in Monitoring Splunk 06-26-2013
3 1
3
1
YisroelB
I am trying to chart initial logins over time as follows: index="abc" sourcetype="*apache_access" NOT remote_ident="...
by YisroelB Explorer in Monitoring Splunk 06-24-2013
1 4
1
4
Get Updates on the Splunk Community!

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...

Data Management Digest – January 2026

Welcome to the January 2026 edition of Data Management Digest! Welcome to the January 2026 edition of Data ...

Splunk SOAR Now Available on Google Cloud Platform

We’re excited to announce that Splunk SOAR is now natively available as a SaaS solution on Google Cloud ...