Splunk Administration

Splunk Administration
Category Activity
jsharvina
i need to index a bunch of xml logs that have an extension of .stats i was able to just upload one of them from the ...
by jsharvina New Member in Getting Data In 06-16-2010
0 3
0
3
maverick
I currently have a 1GB/day Splunk license and I need to have it split up into a smaller 200MB, 300MB, and a 500MB lic...
by maverick Splunk Employee Splunk Employee in Getting Data In 06-16-2010
1 1
1
1
Jaci
I want to upgrade a Splunk device version 3.4.5 build 47883 to version 4.0.11 build 79031. Can I do a direct upgrade...
by Jaci Splunk Employee Splunk Employee in Installation 06-15-2010
1 1
1
1
oreoshake
Do you think splunk could scale to 1 petabyte a day? What is the amount indexed by the largest installation out ther...
by oreoshake Communicator in Getting Data In 06-15-2010
1 2
1
2
dinh
Here's one possible solution I think would work if the there are constant events coming in from each source. search ...
by dinh Path Finder in Getting Data In 06-14-2010
5 6
5
6
mawwx3
I followed the directions for configuring custom timestamps for events with multiple timestamps but I am not getting ...
by mawwx3 Explorer in Getting Data In 06-14-2010
1 6
1
6
jrodman
When i try to train splunk to automatically recognize files of a given type, I get the following: # $SPLUNK_HOME/bin...
by jrodman Splunk Employee Splunk Employee in Getting Data In 06-14-2010
0 1
0
1
kkuminsky
If I specify pollPeriod parameter for fschange, is it supposed to generate an event each time it checks file for chan...
by kkuminsky Path Finder in Getting Data In 06-14-2010
0 2
0
2
Josh
Hi I have a search which is returning the tags in the display, the tags work as I report on these tags in all of our ...
by Josh Path Finder in Knowledge Management 06-14-2010
2 2
2
2
patelbhavin2426
Hi, I am tring to use the Splunk. I am trying to launch the search App. Everytime it looks for updates from the we...
by patelbhavin2426 Observer in Security 06-13-2010
0 1
0
1
Lowell
I'm looking to upgrade my splunk forwarder from a 32-bit Windows version to the 64-bit windows version. Can I simply...
by Lowell Super Champion in Getting Data In 06-12-2010
1 1
1
1
phoenixsecure
Hi, Is there a way to configure how Splunk get the data from WMI for event logs, ex: how often Splunk check the host...
by phoenixsecure Engager in Getting Data In 06-11-2010
1 2
1
2
phoenixsecure
Hi, I defined over 60 hosts in Remote Windows Event log manager on splunk but when I go back in the manager I only s...
by phoenixsecure Engager in Getting Data In 06-11-2010
1 1
1
1
Michael_Wilde
If have 100 desktops i want to collect a few statistics from.. say every 30s... does Splunk make 100 queries every 3...
by Michael_Wilde Splunk Employee Splunk Employee in Getting Data In 06-11-2010
2 1
2
1
balbano
Hey guys, I currently have a 3-server architecture (2 central indexers with 1 search head). We are looking to have ...
by balbano Contributor in Getting Data In 06-11-2010
1 6
1
6
dskillman
Having trouble getting splunk to start on a Windows 2k8 install. No issues on Linux.
by dskillman Splunk Employee Splunk Employee in Installation 06-11-2010
1 1
1
1
cabodj
We would like to point Splunk to our LDAP, but have the ability to create groups within Splunk. These groups would o...
by cabodj Engager in Security 06-11-2010
1 2
1
2
Chris_R_
I have 10's of thousands of files(tarballs) i want to monitor via batch/sinkhole. [batch:///var/log/archived_files] ...
by Chris_R_ Splunk Employee Splunk Employee in Getting Data In 06-10-2010
1 2
1
2
thinguyen
Hi, At the moment we have had number Ironport appliances deployed but their log files being uploaded to FTP server (...
by thinguyen Engager in Getting Data In 06-10-2010
2 3
2
3
Mick
I run a report every 24 hours, and I want to make the .csv results file available to multiple users afterwards. Can ...
by Mick Splunk Employee Splunk Employee in Getting Data In 06-10-2010
1 3
1
3
kkuminsky
Trying to monitor changes to configuration files. Followed this article: http://www.splunk.com/base/Documentation/4....
by kkuminsky Path Finder in Getting Data In 06-10-2010
1 4
1
4
robvolk
I have splunk hosted on a win2k machine with IIS7.5 running. How do I configure splunk so I can access it from my lo...
by robvolk New Member in Getting Data In 06-10-2010
0 4
0
4
nclarkau
We have users that are in another timezone (30 minutes off the servers) and events in their flashtimeline are appeari...
by nclarkau Path Finder in Getting Data In 06-09-2010
0 2
0
2
pmelchiori
I have four servers in different network with the same Windows Name. I've created a Splunk collector and the logs are...
by pmelchiori Explorer in Deployment Architecture 06-09-2010
1 4
1
4
Will_Hayes
How do I install and configure the Cisco MARS archive add-on on Splunkbase?
by Will_Hayes Splunk Employee Splunk Employee in Getting Data In 06-09-2010
0 3
0
3
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Splunk Asynchronous Forwarding Explained

Splunk asynchronous forwarding is often misunderstood as simply setting autoLBVolume. That is not quite right. ...

55 Days to Go: Secure Your Seat at Splunk University in Denver

Your .conf26 Experience Starts Before Opening Keynote  If Denver is known for its mile-high elevation, Splunk ...

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...
Top Karma Authors