Splunk Administration

Splunk Administration
Category Activity
Voltaire
I have received a few errors from my Light Forwarders on my main Splunk indexer. "received event for unconfigured/d...
by Voltaire Communicator in Installation 05-11-2010
0 1
0
1
MikeyG
Can't find a reference to the following error. What does it mean and how do I fix it? Indexing Significant Warns: W...
by MikeyG Explorer in Getting Data In 05-11-2010
1 4
1
4
dianbo_1
Hi, I cloned an application mysearch from search, and created 2 dashboards --- dashboard1 and dashboard2. Now, i wa...
by dianbo_1 Path Finder in Security 05-11-2010
1 2
1
2
Dan
I'm familiar with some of the system-wide limits and per-user quotas that prevent a Splunk instance from getting over...
by Dan Splunk Employee Splunk Employee in Deployment Architecture 05-10-2010
3 1
3
1
MU_IT
I would like to aggregate data from my NPS servers for helpdesk/support use. I have set up a custom index on each se...
by MU_IT New Member in Getting Data In 05-10-2010
0 1
0
1
seanlon11
On my Unix system: I have installed Splunk to: /opt/splunk/ However, now I'd like to move it to: /opt/splunk/serve...
by seanlon11 Path Finder in Installation 05-10-2010
0 2
0
2
sipapress2go
How do I secure my log file stream from our primary server to our dedicated Splunk server? Are there any secured laye...
by sipapress2go Engager in Getting Data In 05-10-2010
1 7
1
7
hulahoop
For indexer requirements, the following is listed as the recommendation configuration in the Planning Your Splunk Dep...
by hulahoop Splunk Employee Splunk Employee in Deployment Architecture 05-10-2010
1 3
1
3
ravi_shah01
Hi, I have a requirement to extract all the events in a file. Example: For an order number, there are around 100 e...
by ravi_shah01 Engager in Getting Data In 05-10-2010
0 2
0
2
vbumgarn
Is there any way to prepopulate the Time Picker via a URL parameter? I need to build a search dynamically in an exte...
by vbumgarn Path Finder in Getting Data In 05-08-2010
2 3
2
3
jeff
Windows Server 2008 R2 x64 (Windows AD Domain Controller) / Splunk 4.1.1 set up as a full forwarder (custom app via d...
by jeff Contributor in Getting Data In 05-07-2010
1 4
1
4
tepperso
I stupidly enabled Lightweight forwarding from the web interface and now I can't get the web interference to load. H...
by tepperso Engager in Deployment Architecture 05-07-2010
0 2
0
2
hans
Here is a sample log: 2010-05-06 16:41:18,082 INFO SplunkCLI :: Executing: "/Users/hs/bin/" status space Th...
by hans Splunk Employee Splunk Employee in Getting Data In 05-07-2010
0 2
0
2
Justin_Grant
We're building an app for WebSphere. We're prefixing all the app's sourcetypes with "WebSphere:" to disambiguate them...
by Justin_Grant Contributor in Getting Data In 05-07-2010
1 1
1
1
mctester
We are looking at upgrading to 4.1.x of splunk, which I have the documentation for. However, I've also been asked to ...
by mctester Communicator in Installation 05-06-2010
1 3
1
3
chris
Hi We recently had a problem with one type of our indexed log files suddenly being recognized as binary. This is t...
by chris Motivator in Getting Data In 05-06-2010
1 4
1
4
kevintelford
So, say we had a dataset with 5 fields, 20 trillion rows. I assume the csv file would be smaller when indexed, but...
by kevintelford Path Finder in Getting Data In 05-05-2010
1 8
1
8
AthlonRob
Is it possible to somehow configure the "default" index on a per-host basis? We have several lightweight forwarders ...
by AthlonRob Engager in Getting Data In 05-05-2010
1 1
1
1
Lowell
Are there any reason to setup both [monitor://] and a [fschange:] inputs for a single path? Are there any problems w...
by Lowell Super Champion in Deployment Architecture 05-05-2010
1 3
1
3
mctester
I was moving some buckets around to make some space on my main storage volume. I know the db_* directories are compl...
by mctester Communicator in Deployment Architecture 05-05-2010
3 5
3
5
clyde772
Would I be able to rename a "Source Type" after the data got already indexed into Splunk? Can I rename a type of pat...
by clyde772 Communicator in Getting Data In 05-05-2010
1 2
1
2
mctester
On the system affected, I cannot visit the "Manager" page under any the apps except search. I tried to visit the "man...
by mctester Communicator in Security 05-04-2010
0 1
0
1
mctester
The splunk cold storage file system is 100% full. I'm relatively new to splunk & not sure the proper way to purge.
by mctester Communicator in Deployment Architecture 05-04-2010
0 3
0
3
jeff
Situation: SSL enabled SplunkWeb. Enterprise evaluation license. Upon connecting to the log-in page, users are presen...
by jeff Contributor in Security 05-04-2010
0 2
0
2
mkinner
I recently upgraded to 4.1.2 from 3.4.x. I needed to remove several hosts from our index, so I followed the instruct...
by mkinner Explorer in Getting Data In 05-04-2010
1 2
1
2
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Karma Authors