Splunk Administration

Splunk Administration
Category Activity
clyde772
1
1
clyde772
I have seen manytime where Splunk didn't copped either multi or single line data correctly ending up with events that...
by clyde772 Communicator in Getting Data In 05-01-2010
0 1
0
1
Ron_Naken
I have an ISA web log of the following format. Splunk doesn't correctly identify the timestamp in every event, even ...
by Ron_Naken Splunk Employee Splunk Employee in Getting Data In 04-30-2010
4 2
4
2
mctester
I had the Unix app running for a while on this instance and that was indexing a lot of data so I disabled the 'os' in...
by mctester Communicator in Deployment Architecture 04-30-2010
1 1
1
1
Steve_Litras
I'm trying to get Splunk SSO working with MS - Forefront TMG (we're thinking about deploying it as our proxy solution...
by Steve_Litras Path Finder in Security 04-30-2010
0 2
0
2
jbidinger
I am trying to implement file integrity monitoring. I have configured fschange as follows: [fschange:/opt/bea/10_sp0...
by jbidinger Explorer in Getting Data In 04-30-2010
0 6
0
6
dave_duvall
I have an "app" that I deploy with my 4.x deployment server. It sends savedsearches.conf, tags.conf, props.conf, eve...
by dave_duvall Explorer in Deployment Architecture 04-30-2010
0 2
0
2
Lowell
Anyone know the best way to monitor deployment activity of a splunk server? I've found DeploymentMetrics coming from...
by Lowell Super Champion in Deployment Architecture 04-30-2010
0 1
0
1
micropotato
I see the same host in my Summary page in Search app with same event count. They are the same host but show up like:...
by micropotato Engager in Getting Data In 04-30-2010
1 1
1
1
the_wolverine
In configuring Splunk to use LDAP, I'm seeing the following error in splunkd.log: ERROR authenticationManagerLDAP...
by the_wolverine Champion in Security 04-30-2010
0 1
0
1
dave_duvall
I'm in the process of upgrading my deployment server to 4.x. I don't push configuration change that often and I hav...
by dave_duvall Explorer in Deployment Architecture 04-29-2010
0 2
0
2
Simon
Hi everybody At the moment I've got about 170 indexes on my indexer. I What's the best practice limit of numbers of...
by Simon Contributor in Getting Data In 04-29-2010
0 2
0
2
Lowell
Can someone shed light on the purpose of the _s _st and _h indexed fields? These seem to correspond to source, sourc...
by Lowell Super Champion in Getting Data In 04-29-2010
0 2
0
2
mzorzi
I have a pair of Search Servers A + B , these are fronted by a Load Balancer so the users just go to a single IP Addr...
by mzorzi Splunk Employee Splunk Employee in Security 04-28-2010
2 2
2
2
Dan
I'm having an issue with my summary index. I have a search which results in 48000+ events. I saved the search and en...
by Dan Splunk Employee Splunk Employee in Knowledge Management 04-28-2010
1 1
1
1
maverick
Regarding agent vs agentless data / event gatering, WMI (agentless) seems easier to setup from within Splunk to pull ...
by maverick Splunk Employee Splunk Employee in Getting Data In 04-28-2010
1 2
1
2
the_wolverine
I've written a bunch of scheduled searches for a Splunk app. The searches appear as having no owner. How can I spec...
by the_wolverine Champion in Security 04-28-2010
3 3
3
3
Hazel
Hello, We have an application called "F2B_Env", this used to work, but now when we try to open it from splunk web, w...
by Hazel Communicator in Security 04-27-2010
0 3
0
3
muebel
My indexer has a Intel Xeon X5570 which has four cores. http://ark.intel.com/Product.aspx?id=37111 How can I make s...
by SplunkTrust SplunkTrust in Getting Data In 04-27-2010
1 1
1
1
bc_unixadm
How can I tell which servers in my enterprise are forwarding to the master server. We do automated installs of vm's a...
by bc_unixadm Explorer in Getting Data In 04-27-2010
1 5
1
5
maverick
Can Splunk index events from my Checkpoint firewall logs? If so, how can I set that up?
by maverick Splunk Employee Splunk Employee in Getting Data In 04-27-2010
1 4
1
4
jmeissner
tried to install splunk on HP-UX and received following error: /opt/instance/splunk/bin/splunk enable boot-start --a...
by jmeissner Splunk Employee Splunk Employee in Installation 04-26-2010
1 2
1
2
jradkowskiAAMC
Currently, all agents installed on hosts default to 'changeme' and this credential is still used when the forwarder i...
by jradkowskiAAMC Explorer in Getting Data In 04-26-2010
0 2
0
2
sivakumar_inbox
I had configured splunk forwarder and receiver in a Linux system as per the Admin manual. I tried searching the forwa...
by sivakumar_inbox Engager in Getting Data In 04-26-2010
1 2
1
2
maverick
I need to push out a new admin password to all of my remote Splunk instances/forwarders. Can I use Splunk Deployment...
by maverick Splunk Employee Splunk Employee in Deployment Architecture 04-26-2010
1 6
1
6
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...

Join the Final Session of the Data Management & Federation Bootcamp Series

Over the past three sessions of the Data Management & Federation Bootcamp Series, we've explored how to build ...

From Data to Insight: Announcing the Winners of the Splunk Dashboard Contest

Hi Splunkers, First off, thank you to everyone who participated in our very first From Data to Insight: The ...
Top Karma Authors