Splunk Administration

Splunk Administration
Category Activity
mctester
I was moving some buckets around to make some space on my main storage volume. I know the db_* directories are compl...
by mctester Communicator in Deployment Architecture 05-05-2010
3 5
3
5
clyde772
Would I be able to rename a "Source Type" after the data got already indexed into Splunk? Can I rename a type of pat...
by clyde772 Communicator in Getting Data In 05-05-2010
1 2
1
2
mctester
On the system affected, I cannot visit the "Manager" page under any the apps except search. I tried to visit the "man...
by mctester Communicator in Security 05-04-2010
0 1
0
1
mctester
The splunk cold storage file system is 100% full. I'm relatively new to splunk & not sure the proper way to purge.
by mctester Communicator in Deployment Architecture 05-04-2010
0 3
0
3
jeff
Situation: SSL enabled SplunkWeb. Enterprise evaluation license. Upon connecting to the log-in page, users are presen...
by jeff Contributor in Security 05-04-2010
0 2
0
2
mkinner
I recently upgraded to 4.1.2 from 3.4.x. I needed to remove several hosts from our index, so I followed the instruct...
by mkinner Explorer in Getting Data In 05-04-2010
1 2
1
2
clyde772
It it possible to get the result of current splunk index to a new index files as a new source type? [ Already indexe...
by clyde772 Communicator in Getting Data In 05-04-2010
0 3
0
3
cdavidy
My Splunk server is listening to UDP port 514 for syslog information. How can I route data to a given index based on...
by cdavidy Explorer in Getting Data In 05-03-2010
0 1
0
1
bfaber
Is there anyway to run an sql like 'plan' on a splunk search to determine efficiency?
by bfaber Communicator in Monitoring Splunk 05-03-2010
5 4
5
4
clyde772
Another License questions, If the Enterprise Demo license got converted to Free license, Then purchase enterprise li...
by clyde772 Communicator in Installation 05-03-2010
3 2
3
2
clyde772
1
1
clyde772
I have seen manytime where Splunk didn't copped either multi or single line data correctly ending up with events that...
by clyde772 Communicator in Getting Data In 05-01-2010
0 1
0
1
Ron_Naken
I have an ISA web log of the following format. Splunk doesn't correctly identify the timestamp in every event, even ...
by Ron_Naken Splunk Employee Splunk Employee in Getting Data In 04-30-2010
4 2
4
2
mctester
I had the Unix app running for a while on this instance and that was indexing a lot of data so I disabled the 'os' in...
by mctester Communicator in Deployment Architecture 04-30-2010
1 1
1
1
Steve_Litras
I'm trying to get Splunk SSO working with MS - Forefront TMG (we're thinking about deploying it as our proxy solution...
by Steve_Litras Path Finder in Security 04-30-2010
0 2
0
2
jbidinger
I am trying to implement file integrity monitoring. I have configured fschange as follows: [fschange:/opt/bea/10_sp0...
by jbidinger Explorer in Getting Data In 04-30-2010
0 6
0
6
dave_duvall
I have an "app" that I deploy with my 4.x deployment server. It sends savedsearches.conf, tags.conf, props.conf, eve...
by dave_duvall Explorer in Deployment Architecture 04-30-2010
0 2
0
2
Lowell
Anyone know the best way to monitor deployment activity of a splunk server? I've found DeploymentMetrics coming from...
by Lowell Super Champion in Deployment Architecture 04-30-2010
0 1
0
1
micropotato
I see the same host in my Summary page in Search app with same event count. They are the same host but show up like:...
by micropotato Engager in Getting Data In 04-30-2010
1 1
1
1
the_wolverine
In configuring Splunk to use LDAP, I'm seeing the following error in splunkd.log: ERROR authenticationManagerLDAP...
by the_wolverine Champion in Security 04-30-2010
0 1
0
1
dave_duvall
I'm in the process of upgrading my deployment server to 4.x. I don't push configuration change that often and I hav...
by dave_duvall Explorer in Deployment Architecture 04-29-2010
0 2
0
2
Simon
Hi everybody At the moment I've got about 170 indexes on my indexer. I What's the best practice limit of numbers of...
by Simon Contributor in Getting Data In 04-29-2010
0 2
0
2
Lowell
Can someone shed light on the purpose of the _s _st and _h indexed fields? These seem to correspond to source, sourc...
by Lowell Super Champion in Getting Data In 04-29-2010
0 2
0
2
mzorzi
I have a pair of Search Servers A + B , these are fronted by a Load Balancer so the users just go to a single IP Addr...
by mzorzi Splunk Employee Splunk Employee in Security 04-28-2010
2 2
2
2
Dan
I'm having an issue with my summary index. I have a search which results in 48000+ events. I saved the search and en...
by Dan Splunk Employee Splunk Employee in Knowledge Management 04-28-2010
1 1
1
1
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...
Top Karma Authors