Monitoring Splunk

Monitoring Splunk
Community Activity
sf_user_199
02-15-2012 10:35:05.421 -0800 ERROR ScriptRunner - extern write error: errno=Broken pipe Any idea what this means? ...
by sf_user_199 Path Finder in Monitoring Splunk 08-03-2012
1 1
1
1
rtkelly
Does anyone know of a Windows port of Bonnie++, or another benchmarking tool that provides the same information on IO...
by rtkelly Explorer in Monitoring Splunk 08-02-2012
1 3
1
3
crazyeva
I have done "splunk clean eventdata -index XXX" on indexers and cleaned "fishbucket" on forwarders problem occurs whe...
by crazyeva Contributor in Monitoring Splunk 07-31-2012
1 3
1
3
seanp
I am trying to configure the FISMA application on a Splunk 4.3 installation using Windows. Specifically I am configu...
by seanp Path Finder in Monitoring Splunk 07-30-2012
0 1
0
1
lee28
Hi, We ran a search command(just count the total event) and got the following results. (using 3 indexers) total event...
by lee28 New Member in Monitoring Splunk 07-27-2012
0 1
0
1
niwenofu
I am trying out splunk but I cannot seem to connect the program to my server. How do i do this?
by niwenofu Engager in Monitoring Splunk 07-24-2012
1 3
1
3
clyde772
Hey Splunkers, Anyone who knows about setting up splunk forwarder as a load balancer to aggregate lower forwarder? ...
by clyde772 Communicator in Monitoring Splunk 07-23-2012
0 1
0
1
khyoung7410
Hi Specifically Is there a way to improve performance? Two of the indexer and search my splunk configuration header ...
by khyoung7410 Communicator in Monitoring Splunk 07-23-2012
0 2
0
2
MJ
Hi, I am planning to install a Splunk indexer on a VM machine and get data from forwarders which are installed on App...
by MJ Engager in Monitoring Splunk 07-20-2012
0 2
0
2
krussell101
We recently made a copy of our production environment. We are running in AWS. An individual made copies of each pro...
by krussell101 Path Finder in Monitoring Splunk 07-18-2012
1 3
1
3
reedmohn
Is there any way to predetermine what performance to expect from Splunk? We have just installed Splunk, distributed o...
by reedmohn Communicator in Monitoring Splunk 07-13-2012
1 5
1
5
mfeeny1
Hi. Recently I ran btool to see just what stanzas were being honored in various inputs.conf files. My command was: ...
by mfeeny1 Path Finder in Monitoring Splunk 07-09-2012
0 1
0
1
hiteshkanchan
There is one query that I am trying to execute, which gives the CPU and Memory Usage. But there is no sync in the tim...
by hiteshkanchan Communicator in Monitoring Splunk 06-26-2012
0 1
0
1
vaibhavbeohar
Hi while seeing CPU utilization of my server in spunk, i am getting following fields, can you please explain sourc...
by vaibhavbeohar Path Finder in Monitoring Splunk 06-25-2012
0 6
0
6
splunk123_
Hello, is there a possibility to run minimum disk space checks manually? Or, somehow, is there a possibility to disab...
by splunk123_ Explorer in Monitoring Splunk 06-18-2012
0 4
0
4
rriley
Trying to throw away events not wanted from a server - not working. props.conf [WinEventLog:Security] TRANSFORMS-nul...
by rriley New Member in Monitoring Splunk 06-18-2012
0 4
0
4
tonan
I see the websphere index getting updated in my splunk admin window. The logs and sources are there in the WAS app fo...
by tonan Explorer in Monitoring Splunk 06-11-2012
0 1
0
1
khyoung7410
hi in splunkd.log and crash.log this log are full then splunkd down... What does this mean? crash.log (Out of file...
by khyoung7410 Communicator in Monitoring Splunk 06-10-2012
1 4
1
4
npandith
Hello, Couple of months back we deployed a new splunk server 4.2.3 on RHEL 5 server and our old splunk version is 4....
by npandith Explorer in Monitoring Splunk 06-07-2012
0 1
0
1
imacdonald2
I tried copying over the audit keys from a 4.2 box to a 4.3 box and I am getting Last few lines of stderr (may con...
by imacdonald2 Path Finder in Monitoring Splunk 05-31-2012
1 3
1
3
itsomana
Hi, I am running the following saved search every 10 minutes which will send an email if *xception is found in the...
by itsomana Path Finder in Monitoring Splunk 05-30-2012
0 2
0
2
Nicholas_Key
It seems that Splunk is only indexing the sourcetype defined last (in this example, it's WebSphere:SystemOutErrLog) w...
by Nicholas_Key Splunk Employee Splunk Employee in Monitoring Splunk 05-29-2012
1 8
1
8
GreenKey
Why does splunkd close internal sockets before the receive queue has been emptied? This appears to leave them laying ...
by GreenKey Engager in Monitoring Splunk 05-29-2012
4 3
4
3
tedder
I know how to get my indexing volume per index. Here's what I use. index="_internal" source="*metrics.log" per_index...
by tedder Communicator in Monitoring Splunk 05-27-2012
5 1
5
1
j666gak
Hello, I am currently running a trial of Splunk which finishes at the end of the week. This morning there is a messa...
by j666gak Communicator in Monitoring Splunk 05-25-2012
0 3
0
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...
Top Solution Authors