Splunk Administration

Splunk Administration
Category Activity
Michael_Wilde
I'm monitoring CPU usage on a Windows server. What's the best way to create a search/alert if CPU usage goes over 80...
by Michael_Wilde Splunk Employee Splunk Employee in Getting Data In 06-28-2010
3 1
3
1
nigelowen
I set the custom time to June 14 11:48:00 -> June 14 11:48:05. I then click on search and the log info is shown but ...
by nigelowen New Member in Getting Data In 06-28-2010
0 2
0
2
aaronnicoli
Hi there, I am in the process of planning a roll out of splunk to our network, however, I am stuck on the indexes. I...
by aaronnicoli Path Finder in Getting Data In 06-28-2010
0 6
0
6
heterodyned
Is there anyway I could verify if there is any variable which could be used to extract hostname for inputs.conf? inst...
by heterodyned Path Finder in Getting Data In 06-27-2010
0 4
0
4
kongchantem
I'm running splunk version 4.0.7 on Windows Server 2008 SP2 x86-64. It's work fine for a couple months. After environ...
by kongchantem Engager in Getting Data In 06-26-2010
1 1
1
1
Dan
I am indexing data feeds A and B and want to forward just data from B as syslog to servers X and Y (cloning the data ...
by Dan Splunk Employee Splunk Employee in Getting Data In 06-26-2010
1 3
1
3
Lowell
How do you properly set a source matching stanza in props to be lower than the default stanza matching priority? Per...
by Lowell Super Champion in Getting Data In 06-26-2010
2 3
2
3
Michael_Wilde
I have a logfile that has headers in the first two lines of the file. Imagine something like the output of UNIX' "to...
by Michael_Wilde Splunk Employee Splunk Employee in Getting Data In 06-25-2010
0 1
0
1
mawwx3
My events have two different times in them, one from when the dns server processed them, and then another is added to...
by mawwx3 Explorer in Getting Data In 06-25-2010
1 5
1
5
nbennett
I have a linux indexer. I forward with the light forwarder from about 200 windows boxes. On the indexer I don't wan...
by nbennett New Member in Getting Data In 06-25-2010
0 3
0
3
Lionel
I am logged as Admin in my system and I noticed that the "Global Summary dashboard" does take into consideration all ...
by Lionel Splunk Employee Splunk Employee in Security 06-25-2010
2 2
2
2
juanb
License Violations continue daily even though I have taken the daily indexing down below the Allowance. With a 500Mb ...
by juanb Explorer in Installation 06-25-2010
1 6
1
6
hiddenkirby
i am not recieving any xml for /services/search/jobs/<sid>/events ... but i get xml for /services/search/jobs/<sid>/...
by hiddenkirby Contributor in Getting Data In 06-25-2010
2 3
2
3
jambajuice
We've got Splunk running on a Windows 2003 R2 x64 server with 8 GB of memory, and two dual-core 3.0 GHz processors. ...
by jambajuice Communicator in Monitoring Splunk 06-25-2010
1 3
1
3
Lowell
Anyone know if it's possible to deploy different apps based on the clients build or version number? I thought I had ...
by Lowell Super Champion in Deployment Architecture 06-24-2010
1 3
1
3
heterodyned
I am planning to integrate Splunk data with MARS, would the cloning option work for Non-Splunk receiver as well? Or i...
by heterodyned Path Finder in Getting Data In 06-24-2010
1 5
1
5
jambajuice
We are trying to filter events from the Windows Event Log that are pulled using WMI. Here is the transforms.conf: [...
by jambajuice Communicator in Getting Data In 06-24-2010
0 4
0
4
Mike_Spellane
I installed the splunk for cisco security app, and at first the firewall overview dashboard worked great, but after a...
by Mike_Spellane New Member in Security 06-24-2010
0 5
0
5
bryancrabtree
I am trying to link events from two separate sourcetypes together that have different fields available. The "corps_ap...
by bryancrabtree Engager in Getting Data In 06-24-2010
3 1
3
1
Voltaire
I received this error in the Windows app after configuring the app and 4.1.2 upgrade. When the app loads its defaul...
by Voltaire Communicator in Installation 06-24-2010
3 6
3
6
Jaci
I would like to know how to automate the package to install across a few hundred servers. I can install the pkg m...
by Jaci Splunk Employee Splunk Employee in Installation 06-24-2010
1 7
1
7
snowmizer
I'm trying to set up fschange to monitor a folder on one of our servers (running Splunk v4.1.2) using the following s...
by snowmizer Communicator in Getting Data In 06-24-2010
1 3
1
3
westar
I need to run a shell script or Linux command inside my search to obtain external Ldap information. I have a UserID ...
by westar Engager in Getting Data In 06-24-2010
2 3
2
3
alankar
How can we specify authorization at data input source level? Like I created a TCP source, but I want it to be availab...
by alankar Engager in Security 06-23-2010
2 1
2
1
cbscribe
I’m building a report that finds the number of unique users in our activity log each day: sourcetype="accountTransac...
by cbscribe Explorer in Knowledge Management 06-23-2010
1 4
1
4
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Karma Authors