Splunk Administration

Splunk Administration
Category Activity
Jason
Is a splunkd restart required for pulling in new edits to serverclass.conf? Or is this file polled every time the Dep...
by Jason Motivator in Deployment Architecture 07-14-2010
2 2
2
2
Jason
Here's an odd one. Anyone run into this before? I am at a client and have put together a package based on this answe...
by Jason Motivator in Getting Data In 07-14-2010
0 3
0
3
riderofyamaha
im doing a username search and i want two fields in my results table to be the time the user sarted the connection an...
by riderofyamaha Explorer in Getting Data In 07-14-2010
0 5
0
5
micah1683
Is there any way to monitor the attributes of files such as 'Date Created' or 'Modified Date' rather than modify the ...
by micah1683 Engager in Getting Data In 07-14-2010
1 1
1
1
klkumar10
I installed Splunk on a Windows DC and configured it as Light Forwarder to send the events to a linux based Splunk In...
by klkumar10 Explorer in Getting Data In 07-14-2010
0 1
0
1
Derek
I have a user who did something that is now prompting for a splunk restart. Is there any way to determine what confi...
by Derek Path Finder in Installation 07-14-2010
0 2
0
2
seanlon11
From server1, I have access to the desired UNC path, and this same user is running splunk, so I know access is not an...
by seanlon11 Path Finder in Getting Data In 07-13-2010
1 4
1
4
antollinim
Hello, I have an enterprise license in one Splunk instance. I would like to add a second Splunk server running with ...
by antollinim New Member in Installation 07-13-2010
0 1
0
1
chicodeme
It seems that splunk has some things to work on when rolling out its product to large corporate environments. We have...
by chicodeme Communicator in Security 07-12-2010
0 6
0
6
matt
I'd like to see a search that will show me who is logged in currently. Anyone know how to do this?
by matt Splunk Employee Splunk Employee in Security 07-11-2010
0 2
0
2
broller25
How may I reset a SplunkLightForwarder so that it will start from scratch and re-forward all data again? (v4.1.3)
by broller25 Explorer in Getting Data In 07-11-2010
2 2
2
2
skippylou
I see you can enable/disable a light forwarder via the gui or cli, but can't seem to dig up the conf file that contai...
by skippylou Communicator in Deployment Architecture 07-10-2010
1 1
1
1
b1nki3
Hello: If an index is kept small due to a low default setting, how can I have splunk reindex a large pool of data on...
by b1nki3 Explorer in Getting Data In 07-09-2010
0 1
0
1
Brian
I am monitoring a directory with contains files that are rotated. Example: A file, today.logs is currently being p...
by Brian Engager in Getting Data In 07-09-2010
1 1
1
1
robp
I have 200+ light forwarders. I use deployment servers to manage their configuration. Can I use the deployment serv...
by robp Engager in Deployment Architecture 07-09-2010
1 5
1
5
Chris_R_
This configuration is two 3.4.2 forwarders -> two 4.1.2 indexers. Forwarders have two UDP inputs & two seperate assig...
by Chris_R_ Splunk Employee Splunk Employee in Getting Data In 07-09-2010
0 2
0
2
apro
Hi, Have tried to install splunk on windows server 2003 and the following error occurs for splunkd and splunkweb: S...
by apro Path Finder in Installation 07-09-2010
0 5
0
5
stefanlasiewski
I'm evaluating Splunk 4.1 (build 77833) on my Mac laptop. Splunk has been turned off since April. When I started Spl...
by stefanlasiewski Contributor in Installation 07-08-2010
0 2
0
2
pj
I am indexing a log file of about 50,000 single line events and for the most part the events are indexed fine. This r...
by pj Contributor in Getting Data In 07-08-2010
0 2
0
2
maverick
I'm trying to install FreeBSD Splunk server on OpenBSD v4.0, but so far no luck. Therefore, I'm thinking the answer...
by maverick Splunk Employee Splunk Employee in Installation 07-08-2010
1 3
1
3
mzorzi
My Indexer is receiving data from a Forwarder but also sending data to non Splunk device. This external device becam...
by mzorzi Splunk Employee Splunk Employee in Getting Data In 07-08-2010
2 5
2
5
lguinn2
When I configure network inputs (TCP or UDP), I provide the port number and sourcetype, but there is nowhere to speci...
by Legend in Getting Data In 07-07-2010
1 5
1
5
dianbo_1
Hi, There are several questions about timezone configuration. I know that splunk use the timezone information in r...
by dianbo_1 Path Finder in Getting Data In 07-07-2010
0 3
0
3
riderofyamaha
When i try and run a multiple input search running 4.1.2 on windows 7 im getting an error message that causes search ...
by riderofyamaha Explorer in Getting Data In 07-07-2010
0 3
0
3
hiddenkirby
Or can i enable "applicationx" with its own inputs.conf. only the lightweightforwarder and the "applicationx" apps a...
by hiddenkirby Contributor in Getting Data In 07-07-2010
0 3
0
3
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...
Top Karma Authors