Splunk Administration

Splunk Administration
Category Activity
silvermail
Hello all, Not sure if anyone has encountered this before, but I have events that are purged off but when I am in th...
by silvermail Path Finder in Getting Data In 08-19-2010
0 3
0
3
silvermail
Hello guys, Been trying to get this to work but to no avail... I have a CSV file that goes like this: pid hostname...
by silvermail Path Finder in Getting Data In 08-19-2010
0 3
0
3
aaronzabell
Splunk is currently indexing the logs for all of my companies switches and routers. It's a mishmash of Dell and Cisco...
by aaronzabell Path Finder in Getting Data In 08-18-2010
0 2
0
2
Nicholas_Key
Hi all, is there a way to translate this event into a table? This is what I get with my search string: index="vmware...
by Nicholas_Key Splunk Employee Splunk Employee in Getting Data In 08-18-2010
0 5
0
5
Branden
Hi. Seems like a lot of people have a question similar to this, but maybe I am missing something simple. I'm monit...
by Branden Builder in Getting Data In 08-18-2010
1 6
1
6
parallaxed
Looks like MetaData:Source should be used, but despite many variations and | extract reload=t, I can't seem to get th...
by parallaxed Path Finder in Getting Data In 08-18-2010
0 4
0
4
matt
Is there a way to specify an alternate location for a Splunk forwarder to do its Splunk crash dumps?
by matt Splunk Employee Splunk Employee in Deployment Architecture 08-18-2010
0 5
0
5
edgustaf
We run a central Syslog-NG server, which all the logs for the servers and devices we care about get sent to. We use ...
by edgustaf Explorer in Getting Data In 08-17-2010
3 4
3
4
erga00
I have a folder containing logs as below. I want to exclude all directories not named DONTINDEX_* and index the conte...
by erga00 Path Finder in Getting Data In 08-17-2010
3 6
3
6
stjack99
I need help figuring out how to store visitor session info into a summary index. First, what I want to be able to do...
by stjack99 Explorer in Knowledge Management 08-17-2010
1 1
1
1
rotten
I've noticed that the maxDist value in the props.conf on various lightweight forwarders varies. I've never explicit...
by rotten Communicator in Getting Data In 08-17-2010
1 1
1
1
bmorgan
You can you backfill to fill in missing pieces, but what happens when splunk or syslog run behind and events run part...
by bmorgan Explorer in Knowledge Management 08-17-2010
2 1
2
1
sgtquezada
I am trying to configure a GET workflow action that decodes a session Id. The problem is that you have to pass the c...
by sgtquezada New Member in Knowledge Management 08-17-2010
0 1
0
1
timbCFCA
Can the Cisco Firewall addon be restricted to only analyze data from a specific source or sourcetype? I have reports...
by timbCFCA Path Finder in Getting Data In 08-17-2010
0 2
0
2
rroberts
What is the significance of cumulative_hits below? Search match hits? number of events returned from a search? 07-09...
by rroberts Splunk Employee Splunk Employee in Monitoring Splunk 08-17-2010
1 3
1
3
tpaulsen
Hello, i seem to have a basic missunderstanding how the Splunk 4.1.3 Deployment Server works. I want to deploy a simp...
by tpaulsen Contributor in Deployment Architecture 08-17-2010
2 13
2
13
ruiaires
We've been having severe Splunk performance issues on the following system: Windows 2008 R2 Enterprise 64 with a 2 C...
by ruiaires Path Finder in Getting Data In 08-17-2010
0 3
0
3
muebel
I would like to install IIS on a Splunk Indexer. Is there any way that this would cause any issues?
by SplunkTrust SplunkTrust in Getting Data In 08-17-2010
1 1
1
1
Joffer
Lets say I have this simple serverClasses: [global] whitelist.0 = * [serverClass:Windows] machineTypes = windows-in...
by Joffer Path Finder in Deployment Architecture 08-17-2010
2 7
2
7
matt
Can I set up a role to access the jobs, but not give them the ability to administer all objects on the system? It see...
by matt Splunk Employee Splunk Employee in Security 08-17-2010
0 1
0
1
jbidinger
I'm trying to monitor the xml files that define a Solaris service. These files live under /var/svc/manifest/.../*.xml...
by jbidinger Explorer in Getting Data In 08-16-2010
1 5
1
5
mpatnode
I tried "splunk train sourcetype filename sourcename" and received the same error. Then I found this answer and got...
by mpatnode Path Finder in Getting Data In 08-16-2010
1 2
1
2
kris2000
Hello All I have Splunk 4.1.4 (splunk-4.1.4-82143-Linux-i686.tgz) installed (on Linux i686 box). I'm currently f...
by kris2000 Explorer in Getting Data In 08-16-2010
2 6
2
6
maverick
Does Splunk have the ability to use different sets of credentials for different monitoring on Windows? It appears o...
by maverick Splunk Employee Splunk Employee in Getting Data In 08-16-2010
0 1
0
1
mfrost8
We recently started turning on 'autoLB' for our lightweight forwarders. We use the default value of 30 seconds for t...
by mfrost8 Builder in Getting Data In 08-15-2010
0 4
0
4
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Karma Authors