Monitoring Splunk

Monitoring Splunk
Community Activity
gharpe2
How can I find out what is taking up the CPU on a search head? Yesterday the utilization was 20% on avg., and today i...
by gharpe2 Explorer in Monitoring Splunk 04-06-2012
0 2
0
2
maverick
What are the pros / cons of running Splunk on a pure core chip setup vs hyper-threaded cores? It used to be that Spl...
by maverick Splunk Employee Splunk Employee in Monitoring Splunk 04-02-2012
1 1
1
1
Mkbell35
How do we manage the diskspace usage by splunk. Does it get truncate at x number of days?Do we need to setup an aler...
by Mkbell35 Engager in Monitoring Splunk 03-18-2012
1 2
1
2
FiveRiversIT
Hello. I'm completely new to splunking and a novice with this firewall. I'm pretty much trying to monitor bandwidth ...
by FiveRiversIT Engager in Monitoring Splunk 03-16-2012
1 3
1
3
nterry
Does anyone have a list of available appenders for the log.cfg file. We are trying to have splunk and the splunk univ...
by nterry Path Finder in Monitoring Splunk 03-16-2012
0 3
0
3
srw46
I read a while back that there should be two splunkd processes and one splunkweb. We configured our internal process...
by srw46 Path Finder in Monitoring Splunk 03-14-2012
0 3
0
3
wwhitener
Hey all, I have a system that is generating a log that I need to have indexed and pull into Splunk. The system is o...
by wwhitener Communicator in Monitoring Splunk 03-13-2012
0 5
0
5
mhorbul
Hello, I have received the following alerts form Deployment Monitor today. Does it look correctly ? Last week numbe...
by mhorbul Explorer in Monitoring Splunk 03-12-2012
0 1
0
1
rtkelly
When I try to disable the Deployment Monitor from the Manager, I get the following error: Error occurred attempting ...
by rtkelly Explorer in Monitoring Splunk 03-12-2012
0 1
0
1
rgcox1
Is Splunk performance better with Raid 1+0 configured across as many spindles as possible, sharing with the OS -- or ...
by rgcox1 Communicator in Monitoring Splunk 03-09-2012
1 2
1
2
twinspop
I'm using SEDCMD to cleanup (and reduce) iislogs: # remove all path info but the (unique) file name SEDCMD-uritrim =...
by twinspop Influencer in Monitoring Splunk 03-08-2012
0 3
0
3
mcbradford
We just upgraded to Splunk 4.3.1 from 4.3 to address the memory leak issues. We have not updated the UFs since this ...
by mcbradford Contributor in Monitoring Splunk 03-08-2012
0 1
0
1
sameer12sa
Hi I am a new user, who downloaded splunk yesterday and learning to configure for monitoring and searching our produ...
by sameer12sa Engager in Monitoring Splunk 03-07-2012
0 3
0
3
JasonCzerak
So I'm at a loss here. .bashrc and .bash_profile are picked up just fine. however I can't get authorized_keys2 to be...
by JasonCzerak Explorer in Monitoring Splunk 03-05-2012
0 1
0
1
shaunwilde
I am trying to configure Splunk to monitor a service that has some unusual (to me) logging behaviour (unfortunately r...
by shaunwilde Engager in Monitoring Splunk 03-04-2012
0 2
0
2
subhadipc
Hi, I have the following query: ... | eval time_sec = round(time_taken/1000) | chart max(time_sec) as max_respons...
by subhadipc Explorer in Monitoring Splunk 02-27-2012
0 1
0
1
richnavis
Our shop virtualizes everything, including our splunk deployment. We are now looking at re-architecting our solution ...
by richnavis Contributor in Monitoring Splunk 02-16-2012
2 2
2
2
richnavis
I am looking to troubleshoot performance problems (Indexing latency) on my splunk indexers. I noticed that there is...
by richnavis Contributor in Monitoring Splunk 02-10-2012
1 2
1
2
twinspop
Based on retention needs, daily volume and available disk I've broken my group's index into 5 main indexes plus 2 sum...
by twinspop Influencer in Monitoring Splunk 02-10-2012
1 1
1
1
henocqr
Hi I want to drop resolved DNS requests at index time. Windows 2008 DNS log format using Splunk 4.3 Can anyone hel...
by henocqr New Member in Monitoring Splunk 02-02-2012
0 1
0
1
balbano
Hi all, I noticed 2 things today: Doesn't look like my indexers are indexing any login events to the GUI. When go...
by balbano Contributor in Monitoring Splunk 01-31-2012
1 6
1
6
rsia23
I think I deleted my _internal index and its now not showing on my search. However the directory is still growing and...
by rsia23 Explorer in Monitoring Splunk 01-25-2012
0 1
0
1
mark
Hi Splunk Community, Question about Splunk Licensing by example If I have 2 x 100GB license files, creating a 200GB...
by mark Path Finder in Monitoring Splunk 01-22-2012
0 1
0
1
mundus
I have events that look like this: in...
by mundus Path Finder in Monitoring Splunk 01-18-2012
0 1
0
1
southeringtonp
I'm wondering about placing warm/hot indexes on PCIe-attached solid state disk, with rollover to cold on traditional ...
by southeringtonp Motivator in Monitoring Splunk 01-17-2012
9 4
9
4
Get Updates on the Splunk Community!

Agentic Operations Start with Context: Build the Right Data Foundation

Agentic Operations Start with Context: Build the Right Data Foundation   By Courtney Wright, Product Marketing ...

Assisted, Augmented or Agentic? Choose Your Splunk Starting Point

Assisted, Augmented or Agentic? Choose Your Splunk Starting Point   By Courtney Wright, Product Marketing ...

Session 2 | Beyond the Thread: Operationalizing AI with Confidence

Session 2   Beyond the Thread: Operationalizing AI with Confidence    The true power of the Cisco Data Fabric ...