Splunk Administration

Splunk Administration
Category Activity
Chris_R_
I am running a pretty basic search such as this email="someemail@domain.com" OR email="someemail@domain.com" ...
by Chris_R_ Splunk Employee Splunk Employee in Getting Data In 07-27-2010
1 2
1
2
Joffer
I think I found the answer to my question when I was writing it. From http://www.splunk.com/base/Documentation/4.1/A...
by Joffer Path Finder in Getting Data In 07-27-2010
0 2
0
2
simuvid
Hi folks, as DHCP logfiles contain huge headers, with always the same information, i will remove them, befor indexin...
by simuvid Splunk Employee Splunk Employee in Getting Data In 07-27-2010
2 2
2
2
gpingry
which version should I download and install?
by gpingry Engager in Deployment Architecture 07-27-2010
1 1
1
1
remy06
Hi, Just to check, I've a splunk forwarder that shows lesser events indexed than on the splunk indexer.Is it suppose...
by remy06 Contributor in Getting Data In 07-27-2010
0 1
0
1
Ron_Naken
When monitoring an EMC Clarion, the CLI tool to dump the logs simply dumps all logs from the device, including any pr...
by Ron_Naken Splunk Employee Splunk Employee in Getting Data In 07-26-2010
3 1
3
1
dmesler
I'm trying to enable SSO by proxying from Apache w/ mod_auth_kerb. The problems seems to be the contents of Remote-Us...
by dmesler Explorer in Getting Data In 07-26-2010
2 2
2
2
Joffer
I'm getting frustrated with one server ending up in my index with both "hostname" and "hostname.domainname" depending...
by Joffer Path Finder in Getting Data In 07-25-2010
1 2
1
2
fgsit
Why does the Splunk server show up as the only host indexing? We're running 3.x and our free lic is shot because it l...
by fgsit New Member in Knowledge Management 07-25-2010
0 2
0
2
noahjscales
Hi. I have a new 4.1.4 free license install running on a VM. On the same server running Splunk, I have a /var/log th...
by noahjscales Explorer in Getting Data In 07-24-2010
0 2
0
2
jpdubose
We are using SplunkLightForwarder on an AIX box. We don't want port 8000 listening and have no real need for the web...
by jpdubose Explorer in Security 07-23-2010
0 5
0
5
bmorgan
I have many tabs open in my browser. Sometimes the only thing that shows on each tab is the favicon. I often have t...
by bmorgan Explorer in Security 07-23-2010
4 2
4
2
beaudet
I have several public facing web servers on which I want to run Splunk in a light-forwarder configuration. However, ...
by beaudet Explorer in Security 07-22-2010
3 8
3
8
mmattek
We are upgrading from splunk 3 to 4. We previously had sourcetypes with "-" in them. It looks like these aren't suppo...
by mmattek Path Finder in Getting Data In 07-22-2010
1 3
1
3
anantshah
Hello, We are currently using light forwarders on our web boxes to forward iis logs to two indexers. One of the inde...
by anantshah Path Finder in Deployment Architecture 07-22-2010
0 1
0
1
wilsona
I am attempting to evaluate splunk, however the licence terms are too restrictive in order to do a proper eval. To ge...
by wilsona New Member in Installation 07-22-2010
0 4
0
4
Joffer
I've got several windows servers which has got Splunk 4.1.3 installed and even though I disable webserver, configure ...
by Joffer Path Finder in Security 07-22-2010
2 6
2
6
morningwood
We are currently performing a POC using Splunk 4.1.3 to index Blue Coat proxy data. Our test Splunk license is for 20...
by morningwood Explorer in Getting Data In 07-22-2010
1 5
1
5
remy06
Hi, How do I get splunk to show the date and time correctly based on the event?For example if I have the following e...
by remy06 Contributor in Getting Data In 07-22-2010
2 1
2
1
tophdog
Hiya, I work on a very large, maybe the largest unclassified DSEE implementation in existence. I'm starting to look ...
by tophdog New Member in Security 07-22-2010
0 2
0
2
tawollen
Before I go and purchase certificates I wanted to ask a quick question about SSL certificates, in particular wildcard...
by tawollen Path Finder in Security 07-21-2010
1 1
1
1
Jason
I have data coming in in the format "data1","data2","data3" from F5. however, some events contain " and some contain...
by Jason Motivator in Getting Data In 07-21-2010
6 7
6
7
chicodeme
When you install the splunk client by default it will have the following: tcp 0 0 0.0.0.0:8089 ...
by chicodeme Communicator in Security 07-21-2010
1 6
1
6
ehilgendorf
The standard *INX scripts, CPU, MEM, DISK, etc. work fine on my linux servers. But, Not at all on my AIX servers (A...
by ehilgendorf New Member in Deployment Architecture 07-21-2010
0 3
0
3
Michael_Wilde
I've just setup a search head that will search across 2 load balanced indexers.  I'd like to compare the execution ti...
by Michael_Wilde Splunk Employee Splunk Employee in Monitoring Splunk 07-21-2010
1 1
1
1
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...
Top Karma Authors