Splunk Administration

Splunk Administration
Category Activity
Joffer
I've got a Win 2008 Web server, and the layout on the disk is as follow: C:\inetpub\sites\www.fqdn.com\logs\ C:\inet...
by Joffer Path Finder in Getting Data In 08-04-2010
1 8
1
8
chris
Is it possible to forward data from source A to Indexer A and data from source B to Indexer B if I use the light forw...
by chris Motivator in Getting Data In 08-04-2010
2 3
2
3
melonman
Hi, I have been using splunk and unfortunately put all data into main index, but because there is a need to allow m...
by melonman Motivator in Getting Data In 08-03-2010
0 6
0
6
MJTrigwell
Hi, I am having problems getting Splunk to monitor WebSphere V7. I have enabled PMI on WebSphere and installed Splu...
by MJTrigwell Engager in Monitoring Splunk 08-03-2010
2 4
2
4
erydberg
I'm using a scripted input for an application. The script writes warnings to stderr, which makes them show up in splu...
by erydberg Splunk Employee Splunk Employee in Getting Data In 08-03-2010
1 1
1
1
twinspop
My scheduled search: [Summary Logins Per Second] action.summary_index = 1 action.summary_index._name = lgn-stats cro...
by twinspop Influencer in Knowledge Management 08-03-2010
0 2
0
2
Katey
How to send syslog-ng messages to Splunk properly? I'm using Free 'splunk-4.1.4-82143-linux-2.6-intel.deb' and 'syslo...
by Katey Explorer in Getting Data In 08-03-2010
3 4
3
4
bnolen
Is it possible to use the oneshot command from a remote server. Essentially we have a series of logs that are not ab...
by bnolen Path Finder in Getting Data In 08-03-2010
0 4
0
4
Justin_Grant
I have a log, representing data from multiple hosts, with lines like this: 7/30/2010 4:11:52 PM host=OAK06VMH load=5...
by Justin_Grant Contributor in Getting Data In 07-31-2010
1 1
1
1
bfaber
In other words, can I set 30 days OR 700G (for instance)? The docs aren't clear on how to do that.
by bfaber Communicator in Getting Data In 07-31-2010
0 1
0
1
afroblanco
Hello all, I'm new to Splunk, so please bear with me as I ask a really n00bish question. Is it necessary to define y...
by afroblanco Engager in Getting Data In 07-30-2010
1 3
1
3
maverick
On Windows, I want to set the homePath in my indexes.conf file for a new index I created, which is located on my E:\ ...
by maverick Splunk Employee Splunk Employee in Getting Data In 07-30-2010
0 1
0
1
COH
I have a WMI Perf counter query that always returns zero in Splunk as the values are always < 1 second. It looks like...
by COH New Member in Getting Data In 07-30-2010
0 1
0
1
njathan
I am trying to analyse a squid access log for top 10 reports (top sources, top destinations, etc.) I imported the lo...
by njathan Explorer in Getting Data In 07-30-2010
1 5
1
5
zscgeek
In this answer I can see there is ways to get the status of the tailing processor on a box. Only problem is it looks ...
by zscgeek Path Finder in Getting Data In 07-30-2010
0 2
0
2
noahjscales
I turned off the syslog server running alongside Splunk and configured Splunk to listen on 514. It indexed the forwar...
by noahjscales Explorer in Getting Data In 07-30-2010
1 3
1
3
dtrouper
I am getting runtime error R6034 - "Am application has made an attempt to load the C runtime library incorrectly. I ...
by dtrouper New Member in Installation 07-29-2010
0 1
0
1
Sparky
Hi There.. What is the best way to accomplish the following: I have several users who are on XP notebooks who need to...
by Sparky Engager in Getting Data In 07-29-2010
1 1
1
1
miguel255
I have version 4.1 and have it set up to recieve syslog data directly from various servers but I only want to hold th...
by miguel255 Engager in Getting Data In 07-29-2010
1 1
1
1
hbazan
Hi there.Lets see if someone can help me with this. We have this requirement: We have several saved searches and rep...
by hbazan Path Finder in Getting Data In 07-29-2010
2 5
2
5
wollinet
FORMAT = <string> * The special identifier $0 represents what was in the DEST_KEY before this regex was performed. ...
by wollinet Path Finder in Getting Data In 07-29-2010
0 6
0
6
heterodyned
This would be a very trivial question, but what are the circumstances when splunk re-indexes new data? Replacing an e...
by heterodyned Path Finder in Getting Data In 07-29-2010
0 5
0
5
kranthi
Hello , We have splunk 3.4.6 installed on one of our servers locally, on that server it was configured so that it ge...
by kranthi New Member in Getting Data In 07-28-2010
0 1
0
1
Jason
According to the wiki the best practice for syslog is having another program write the files to disk then have Splunk...
by Jason Motivator in Getting Data In 07-28-2010
1 1
1
1
alextsui
Hi, I have used props.conf and transforms.conf to configure two different sourcetypes coming to Splunk from udp:514. ...
by alextsui Path Finder in Getting Data In 07-28-2010
0 3
0
3
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.
Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...
Top Karma Authors