Splunk Administration

Splunk Administration
Category Activity
Chris_R_
What are the id_XX buckets that show up under "index activity", They also show up in the bucket directories. What do ...
by Chris_R_ Splunk Employee Splunk Employee in Deployment Architecture 05-13-2010
0 4
0
4
maverick
If I have a Splunk indexer running on a 32-bit OS and another Splunk indexer running on a 64-bit OS, can I setup Splu...
by maverick Splunk Employee Splunk Employee in Deployment Architecture 05-13-2010
1 2
1
2
Dan
On Splunk 4.1, I see a bunch of these messages. What do they mean? Should I be concerned? 04-28-2010 13:48:32.27...
by Dan Splunk Employee Splunk Employee in Getting Data In 05-13-2010
2 3
2
3
hiddenkirby
So i've set up a form dashboard to filter a query displayed in a table. Is there any way to get a "google suggest" t...
by hiddenkirby Contributor in Security 05-13-2010
1 4
1
4
gljiva
Hi, i saw many suggestions to routing data to different index from light forwarder but none seems to work. I have se...
by gljiva Path Finder in Getting Data In 05-12-2010
3 5
3
5
ericmoss
I am trying to forward event logs from a Windows XP machine to a Windows 2003 machine. I set up Splunk on the Window...
by ericmoss Explorer in Getting Data In 05-12-2010
1 1
1
1
geva
Hey all: I'm very interested in setting Splunk up to have it monitor all of my logs. One of such main requirements ...
by geva Explorer in Getting Data In 05-12-2010
2 10
2
10
aiwatson
The following line is found when I try to restart the stopped splunkd process:- 05-12-2010 14:30:50.819 ERROR WordP...
by aiwatson Engager in Monitoring Splunk 05-12-2010
2 1
2
1
mzorzi
I'm looking for a way to create a minimal light forwarder installation. What can I remove from the standard Splunk de...
by mzorzi Splunk Employee Splunk Employee in Installation 05-12-2010
5 2
5
2
clyde772
I have changed input.conf and restarted Spulnk, but I can't see any event generated for changing /etc/hosts file. Th...
by clyde772 Communicator in Getting Data In 05-12-2010
3 2
3
2
jambajuice
If I have a UDP input defined in /etc/system/local/inputs.conf and I create event filters using a transforms.conf and...
by jambajuice Communicator in Deployment Architecture 05-12-2010
1 1
1
1
rgonzale6
What I'd like is to have the date appended to the file name. Currently we have a scheduled saved search running each...
by rgonzale6 Path Finder in Getting Data In 05-11-2010
0 3
0
3
dave_duvall
So I have a lab box where I have applied 4.0.11 to my existing 4.0.10 installation. Ran the upgrade using rpm -U and...
by dave_duvall Explorer in Installation 05-11-2010
1 2
1
2
balbano
Hey Guys, Just noticed that logging on one of my light forwarders is taking up a lot of space: myhost[05:15 PM]roo...
by balbano Contributor in Deployment Architecture 05-11-2010
1 2
1
2
Voltaire
I have received a few errors from my Light Forwarders on my main Splunk indexer. "received event for unconfigured/d...
by Voltaire Communicator in Installation 05-11-2010
0 1
0
1
MikeyG
Can't find a reference to the following error. What does it mean and how do I fix it? Indexing Significant Warns: W...
by MikeyG Explorer in Getting Data In 05-11-2010
1 4
1
4
dianbo_1
Hi, I cloned an application mysearch from search, and created 2 dashboards --- dashboard1 and dashboard2. Now, i wa...
by dianbo_1 Path Finder in Security 05-11-2010
1 2
1
2
Dan
I'm familiar with some of the system-wide limits and per-user quotas that prevent a Splunk instance from getting over...
by Dan Splunk Employee Splunk Employee in Deployment Architecture 05-10-2010
3 1
3
1
MU_IT
I would like to aggregate data from my NPS servers for helpdesk/support use. I have set up a custom index on each se...
by MU_IT New Member in Getting Data In 05-10-2010
0 1
0
1
seanlon11
On my Unix system: I have installed Splunk to: /opt/splunk/ However, now I'd like to move it to: /opt/splunk/serve...
by seanlon11 Path Finder in Installation 05-10-2010
0 2
0
2
sipapress2go
How do I secure my log file stream from our primary server to our dedicated Splunk server? Are there any secured laye...
by sipapress2go Engager in Getting Data In 05-10-2010
1 7
1
7
hulahoop
For indexer requirements, the following is listed as the recommendation configuration in the Planning Your Splunk Dep...
by hulahoop Splunk Employee Splunk Employee in Deployment Architecture 05-10-2010
1 3
1
3
ravi_shah01
Hi, I have a requirement to extract all the events in a file. Example: For an order number, there are around 100 e...
by ravi_shah01 Engager in Getting Data In 05-10-2010
0 2
0
2
vbumgarn
Is there any way to prepopulate the Time Picker via a URL parameter? I need to build a search dynamically in an exte...
by vbumgarn Path Finder in Getting Data In 05-08-2010
2 3
2
3
jeff
Windows Server 2008 R2 x64 (Windows AD Domain Controller) / Splunk 4.1.1 set up as a full forwarder (custom app via d...
by jeff Contributor in Getting Data In 05-07-2010
1 4
1
4
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...
Top Karma Authors