Splunk Administration

Splunk Administration
Category Activity
Ledio_Ago
Let's say I have a distributed Splunk environment, n indexers, one search head and a forwarder load balancing input d...
by Ledio_Ago Splunk Employee Splunk Employee in Deployment Architecture 05-20-2010
3 2
3
2
phoenixsecure
Hi, I am collecting event logs thru WMI for Windows 2000 and 2003 servers, for 2003 everything seem ok but for 2000 ...
by phoenixsecure Engager in Getting Data In 05-20-2010
2 2
2
2
Chris_R_
How do keep splunk from removing syslog priority fields? They are removed once indexed into splunk.
by Chris_R_ Splunk Employee Splunk Employee in Getting Data In 05-19-2010
0 3
0
3
Yancy
Since I updated our server to 4.1.2 I'm seeing the following error with most searches. The lookup table 'sid_look...
by Yancy Path Finder in Getting Data In 05-19-2010
2 2
2
2
carmackd
Can I use blacklist in a batch stanza? I couldn't find anything in the documentation saying otherwise. Thanks,
by carmackd Communicator in Getting Data In 05-19-2010
2 2
2
2
djfisher
I use the recommended search below to find lost forwarders after a 24hr period. http://www.splunk.com/wiki/Depl...
by djfisher Explorer in Getting Data In 05-19-2010
1 5
1
5
hiddenkirby
IF one wanted to add static highlighted text to the top of every page in their app... how would they go about doing t...
by hiddenkirby Contributor in Security 05-19-2010
1 7
1
7
oreoshake
I'm starting to get a lot of these errors on my forwarders. Any suggestions? Pushing /etc/security/limits.conf does...
by oreoshake Communicator in Getting Data In 05-19-2010
0 2
0
2
seanlon11
How can I easily search through Splunk to figure out which sources are associated with a specific host? I know I c...
by seanlon11 Path Finder in Getting Data In 05-19-2010
1 2
1
2
balbano
Hi all, One of the servers we installed Splunk LF on is having high CPU and Memory Utilization as a result of Splun...
by balbano Contributor in Deployment Architecture 05-19-2010
1 6
1
6
oreoshake
We are using "heavy" forwarders, but I have the following config on both the forwarder and the indexer but the events...
by oreoshake Communicator in Getting Data In 05-18-2010
1 4
1
4
piebob
reposting for a user over on the forums: I bounced my indexer and now my forwarders are unable to connect. I just u...
by piebob Splunk Employee Splunk Employee in Getting Data In 05-18-2010
1 2
1
2
mkinner
Using Splunk server & clients running 4.1.2. When I installed Splunk on our many clients I enabled the SplunkLightFo...
by mkinner Explorer in Deployment Architecture 05-18-2010
1 4
1
4
ostmovid
I use several SplunkLightFirwarders on Suslog-ng servers to have a "buffer" to relatively large amounts of syslog tha...
by ostmovid New Member in Deployment Architecture 05-18-2010
0 9
0
9
balbano
Hey guys, I managed to setup deployment server / client test model with our 2 central indexers and a test sample of...
by balbano Contributor in Deployment Architecture 05-17-2010
0 1
0
1
active
It used to be possible to log a user in to Splunk by sending the username and password in the body of a POST request ...
by active Engager in Security 05-17-2010
2 2
2
2
Lowell
I am having trouble getting _internal and _audit to be forwarder properly when being passed through more than one for...
by Lowell Super Champion in Getting Data In 05-17-2010
1 6
1
6
petru
Hello I have a question about splunk capabilities. I installed splunk on a server (domain member) and I can get th...
by petru Engager in Getting Data In 05-17-2010
1 1
1
1
craigallen
Hi, We have installed Splunk under an eval using just a local username. We'd like to monitor AD, but can't work out ...
by craigallen Engager in Getting Data In 05-17-2010
1 1
1
1
msallman
We are having a problem getting the Windows app to display wmi data. It seems that the wmi data we are getting is bei...
by msallman Explorer in Getting Data In 05-14-2010
0 7
0
7
tbhuy
Hi everybody, I try to download the user and admin manual in pdf format. Unfortunlly, it take me a long time and afte...
by tbhuy New Member in Security 05-14-2010
0 2
0
2
Chris_R_
What are the id_XX buckets that show up under "index activity", They also show up in the bucket directories. What do ...
by Chris_R_ Splunk Employee Splunk Employee in Deployment Architecture 05-13-2010
0 4
0
4
maverick
If I have a Splunk indexer running on a 32-bit OS and another Splunk indexer running on a 64-bit OS, can I setup Splu...
by maverick Splunk Employee Splunk Employee in Deployment Architecture 05-13-2010
1 2
1
2
Dan
On Splunk 4.1, I see a bunch of these messages. What do they mean? Should I be concerned? 04-28-2010 13:48:32.27...
by Dan Splunk Employee Splunk Employee in Getting Data In 05-13-2010
2 3
2
3
hiddenkirby
So i've set up a form dashboard to filter a query displayed in a table. Is there any way to get a "google suggest" t...
by hiddenkirby Contributor in Security 05-13-2010
1 4
1
4
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...
Top Karma Authors