Monitoring Splunk

Monitoring Splunk
Community Activity
vaibhavbeohar
Hi while seeing CPU utilization of my server in spunk, i am getting following fields, can you please explain sourc...
by vaibhavbeohar Path Finder in Monitoring Splunk 06-25-2012
0 6
0
6
splunk123_
Hello, is there a possibility to run minimum disk space checks manually? Or, somehow, is there a possibility to disab...
by splunk123_ Explorer in Monitoring Splunk 06-18-2012
0 4
0
4
rriley
Trying to throw away events not wanted from a server - not working. props.conf [WinEventLog:Security] TRANSFORMS-nul...
by rriley New Member in Monitoring Splunk 06-18-2012
0 4
0
4
tonan
I see the websphere index getting updated in my splunk admin window. The logs and sources are there in the WAS app fo...
by tonan Explorer in Monitoring Splunk 06-11-2012
0 1
0
1
khyoung7410
hi in splunkd.log and crash.log this log are full then splunkd down... What does this mean? crash.log (Out of file...
by khyoung7410 Communicator in Monitoring Splunk 06-10-2012
1 4
1
4
npandith
Hello, Couple of months back we deployed a new splunk server 4.2.3 on RHEL 5 server and our old splunk version is 4....
by npandith Explorer in Monitoring Splunk 06-07-2012
0 1
0
1
imacdonald2
I tried copying over the audit keys from a 4.2 box to a 4.3 box and I am getting Last few lines of stderr (may con...
by imacdonald2 Path Finder in Monitoring Splunk 05-31-2012
1 3
1
3
itsomana
Hi, I am running the following saved search every 10 minutes which will send an email if *xception is found in the...
by itsomana Path Finder in Monitoring Splunk 05-30-2012
0 2
0
2
Nicholas_Key
It seems that Splunk is only indexing the sourcetype defined last (in this example, it's WebSphere:SystemOutErrLog) w...
by Nicholas_Key Splunk Employee Splunk Employee in Monitoring Splunk 05-29-2012
1 8
1
8
GreenKey
Why does splunkd close internal sockets before the receive queue has been emptied? This appears to leave them laying ...
by GreenKey Engager in Monitoring Splunk 05-29-2012
4 3
4
3
tedder
I know how to get my indexing volume per index. Here's what I use. index="_internal" source="*metrics.log" per_index...
by tedder Communicator in Monitoring Splunk 05-27-2012
5 1
5
1
j666gak
Hello, I am currently running a trial of Splunk which finishes at the end of the week. This morning there is a messa...
by j666gak Communicator in Monitoring Splunk 05-25-2012
0 3
0
3
twinspop
Anyone else getting dead splunkds? Unfortunately, the splunkd log isn't giving any useful info. Tips on where else to...
by twinspop Influencer in Monitoring Splunk 05-24-2012
0 6
0
6
kgeil
Hi, I have Splunk set up on my workstation, but do not want to monitor the workstation itself. I have gone to Manage...
by kgeil Explorer in Monitoring Splunk 05-24-2012
0 5
0
5
jaoui
I have several thousand files that are being monitored with a stanza like the following: [/files//.log] when i resta...
by jaoui Path Finder in Monitoring Splunk 05-21-2012
0 1
0
1
TonyOliver
Our enterprise utilizes Citrix to deliver applications to our 5000 users. We are looking to upgrade Citrix or change...
by TonyOliver New Member in Monitoring Splunk 05-18-2012
0 1
0
1
Chubbybunny
Mr. Hare recently installed the PDF server app on the bunny farm and I'm finding the 'status page' link is timing out...
by Chubbybunny Splunk Employee Splunk Employee in Monitoring Splunk 05-09-2012
4 3
4
3
mataharry
Found this error message in my splunkd.log while rebuilding my indexes. Is it serious ? 8:33:19.729 AM 05-09-2012 08...
by mataharry Communicator in Monitoring Splunk 05-09-2012
0 1
0
1
Emblibrary
I currently have Splunk on a central server and 3 other servers forwarding events to it. All the servers have been s...
by Emblibrary Explorer in Monitoring Splunk 05-09-2012
0 1
0
1
mbattaglia
I have a problem to monitor the module Cisco IPS ASA5585-SSP-IPS10 From the IPS I see this error ; the state remain ...
by mbattaglia Engager in Monitoring Splunk 05-08-2012
2 3
2
3
briang67
According to this link, it's possible to send the datastore buckets to different disk volumes to take advantage of di...
by briang67 Communicator in Monitoring Splunk 05-04-2012
0 1
0
1
colinj
_internal and _audit have started to out grow their default location in $SPLUNK_DB. I'd like to relocate them to use ...
by colinj Path Finder in Monitoring Splunk 05-02-2012
0 1
0
1
deyeo
A user created many searches, and the searches are private. Since these searches belong to the owner, before deleting...
by deyeo Path Finder in Monitoring Splunk 04-30-2012
4 2
4
2
Andrew
I've read in the docs that the disk performance should be 800 IOPs. How can I test this when the disk is NFS (I can't...
by Andrew Engager in Monitoring Splunk 04-26-2012
3 2
3
2
misteryuku
I would like to use Splunk to detect Denial of Service log anomaly. I used Wireshark as a source to get log data. i'm...
by misteryuku Communicator in Monitoring Splunk 04-26-2012
0 2
0
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...