Splunk Administration

Splunk Administration
Category Activity
mcalautti
I didnt see any documentation on doing an upgrade to 64b.
by mcalautti Explorer in Installation 05-27-2010
1 2
1
2
ubko
Is there a way to pass the result of a savedsearch to a script? For example, if the search returns: suser duser ...
by ubko Explorer in Getting Data In 05-27-2010
2 2
2
2
sdwilkerson
Some events flow into the Splunk instance via syslog sockets. For a brief period of time, the sourcetypes that came ...
by sdwilkerson Contributor in Getting Data In 05-27-2010
1 3
1
3
lyndac
I have a .csv file that I'm indexing. There is no timestamp information in the .csv file, but there is a date in the...
by lyndac Contributor in Getting Data In 05-27-2010
2 5
2
5
hiddenkirby
strptime() format expression examples Below are some sample date formats with strptime() expressions that handle the...
by hiddenkirby Contributor in Getting Data In 05-27-2010
0 8
0
8
hiddenkirby
The flash module for the map is in front of the nav dropdowns. This a known issue? Any work arounds? Something i ma...
by hiddenkirby Contributor in Security 05-27-2010
0 2
0
2
parallaxed
Splunk always seems to get this wrong. I have the following in a vain effort to correct this TIME_PREFIX=^ TIME_FOR...
by parallaxed Path Finder in Getting Data In 05-27-2010
2 10
2
10
Yancy
Is there a way to set tags based off a wild card value? IE I have the following hosts and I want to apply the 'test'...
by Yancy Path Finder in Getting Data In 05-27-2010
0 2
0
2
dwaddle
Is the output of 'splunk list monitor' clipped at all? I have a directory with (approx) 50 log files, but the outp...
by SplunkTrust SplunkTrust in Monitoring Splunk 05-26-2010
3 4
3
4
msenthilganesh
I am expecting to see each record as an event, but the result is not as expected. Some records are displayed as indi...
by msenthilganesh New Member in Getting Data In 05-26-2010
0 1
0
1
Chris_R_
If we have an indexer configured w/a raid 5 or raid 6 array is this going to negatively affect performance?
by Chris_R_ Splunk Employee Splunk Employee in Getting Data In 05-26-2010
2 4
2
4
littlejef
I am currently running a eval version of Splunk 4.0.9 on a Windows 2008 64Bit Host. Our purchase of Splunk has been a...
by littlejef Engager in Getting Data In 05-26-2010
1 1
1
1
balbano
Hi, we are currently testing a Palo Alto app sec firewall and are sending some test logs over to the central indexer ...
by balbano Contributor in Getting Data In 05-26-2010
0 6
0
6
Genti
I would like to deploy Light Forwarders at our remote locations to act as a syslog server. Can light forwarder be con...
by Genti Splunk Employee Splunk Employee in Getting Data In 05-25-2010
2 2
2
2
smisplunk
I've got a summary index query which currently matches only one (1) event in my existing data. I've run the fill_sum...
by smisplunk Path Finder in Knowledge Management 05-25-2010
0 3
0
3
wdc
I've found how to get data from a remote users Security Log but we are after a centralised area to keep these logs. I...
by wdc New Member in Getting Data In 05-25-2010
0 3
0
3
ASW3382
I am revisiting splunk to see if it will meet our goals. Right now I am working on the initial index of our data gat...
by ASW3382 New Member in Getting Data In 05-24-2010
0 4
0
4
Jaci
Our indexer and all forwarders are running 4.1.2. Recently we developed a need to send events from our forwarders in...
by Jaci Splunk Employee Splunk Employee in Getting Data In 05-24-2010
1 3
1
3
Genti
What is the relationship between size of logs received by Splunk indexing servers versus indexing volume? On the load...
by Genti Splunk Employee Splunk Employee in Getting Data In 05-24-2010
0 1
0
1
Jaci
I have a deployment server app with a single inputs.conf file. [tcp://localhost:9997] sourcetype = tcp-raw index = p...
by Jaci Splunk Employee Splunk Employee in Getting Data In 05-24-2010
1 2
1
2
johnpulley
I want to use Splunk to monitor the error output of a telephone switch. I can easily see the data by connecting to th...
by johnpulley New Member in Monitoring Splunk 05-24-2010
0 5
0
5
jeff
I have the following in inputs.conf: [udp://32004] host = custom_host connection_host = non...
by jeff Contributor in Getting Data In 05-22-2010
3 3
3
3
mctester
Hi, I have a development support question. We have an application that is integrated with splunk. We have a C++ p...
by mctester Communicator in Getting Data In 05-22-2010
2 1
2
1
dcroteau
we only want to save the log info for 2 weeks. I tried to set this up by modifying the frozen time, but it doesn’t s...
by dcroteau Splunk Employee Splunk Employee in Getting Data In 05-22-2010
1 3
1
3
maverick
Suppose I splunk a file and it is gzip'd on disk under the appropriate Splunk index directory. Then let's say I con...
by maverick Splunk Employee Splunk Employee in Getting Data In 05-22-2010
1 1
1
1
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Karma Authors