Splunk Administration

Splunk Administration
Category Activity
splunkbox
After upgrading from 4.0.x (I don't exactly remember the version) to 4.1 in OS X 10.5.8 I get the following log /Ap...
by splunkbox Engager in Installation 04-14-2010
2 3
2
3
lguinn2
Do I need to configure distributed search on all the search peers?
by Legend in Deployment Architecture 04-14-2010
1 2
1
2
kbecker
Is Splunk 4.1 (indexer & search) still compatible with 3.4.11 forwarders? Is so are there any features in 4.1 that w...
by kbecker Communicator in Installation 04-14-2010
2 3
2
3
Simeon
I have a file that I need to index twice. Specifically, I need it sent/indexed to two different indexes. How could...
by Simeon Splunk Employee Splunk Employee in Getting Data In 04-14-2010
1 4
1
4
Jeremiah
How should I allocate space for indexes among indexing nodes? For example, lets say I have 2 groups of servers that ...
by Jeremiah Motivator in Deployment Architecture 04-14-2010
1 1
1
1
cdavidy
I've been asked to look into renaming my Splunk indexer server (don't ask why). Is there a "best" or safe method for...
by cdavidy Explorer in Deployment Architecture 04-14-2010
1 2
1
2
despera
I have Splunk 4.0.10 64bit version running in Windows 2008 R2 64bit. I noticed that when Splunkd service is turned o...
by despera Splunk Employee Splunk Employee in Getting Data In 04-13-2010
2 1
2
1
Dan
I've heard there are some REST endpoints that allow you to refresh objects (such as new dashboards, nav menus, etc......
by Dan Splunk Employee Splunk Employee in Getting Data In 04-13-2010
2 3
2
3
pillowhead
Hi, I just installed cisco_firewall_addon for version 4.1 of splunk and I am having some issues. I have an ASA and a ...
by pillowhead Explorer in Getting Data In 04-13-2010
1 5
1
5
norfleetj
Hello, System type: Linux We have splunk running on our centralized syslog-ng server. We then have other servers fo...
by norfleetj Engager in Getting Data In 04-13-2010
1 4
1
4
hulahoop
Would someone confirm the following observations regarding data input configuration via inputs.conf? when using wild...
by hulahoop Splunk Employee Splunk Employee in Getting Data In 04-13-2010
0 3
0
3
mudricd
Hi, I have syslog_ng server (sles 10). Everything is logged in this way: /var/log/HOSTS/xx-yy/hostname or ip/log fi...
by mudricd Explorer in Getting Data In 04-13-2010
0 2
0
2
jrich523
I just installed Splunk 4.1 (configured to run on system accounts) and the first thing i did was add an input monitor...
by jrich523 Path Finder in Getting Data In 04-12-2010
1 1
1
1
matt
I need to figure out what LDAP values I should be using to make auth work.
by matt Splunk Employee Splunk Employee in Security 04-12-2010
1 3
1
3
Lowell
Does anyone know if alwaysOpenFile still works in inputs.conf as of Splunk 4.1. It still shows up in the 4.1 docs, b...
by Lowell Super Champion in Getting Data In 04-12-2010
1 6
1
6
dskillman
I have a file with ~6M events that gets FTP'd to Splunk on a daily basis. Unfortunately I don't have control of the ...
by dskillman Splunk Employee Splunk Employee in Getting Data In 04-12-2010
1 1
1
1
Alan_Bradley
What is the mechanism for federating credentials between splunk servers when doing a distributed search?
by Alan_Bradley Path Finder in Security 04-11-2010
1 2
1
2
Alan_Bradley
I'd like to convert a busy server with a bunch of users from default auth to LDAP. How can I do so without losing any...
by Alan_Bradley Path Finder in Security 04-11-2010
1 3
1
3
jsondheimer
I am using Splunk to collect data from the security logs on my network. How long does Splunk store the data that it c...
by jsondheimer New Member in Getting Data In 04-09-2010
0 2
0
2
the_wolverine
I have an instance that I've set up to only run summary searches. Essentially, its a search head but no users connec...
by the_wolverine Champion in Knowledge Management 04-09-2010
0 1
0
1
Steve_G_
For example, does Splunk ignore server.conf, distsearch.conf, or any other conf files if they're located in an apps d...
by Steve_G_ Splunk Employee Splunk Employee in Installation 04-09-2010
2 2
2
2
Alan_Bradley
I just upgraded my install to 4.1 and LDAP auth is no longer working. The failsafe user is all I can use. Previousl...
by Alan_Bradley Path Finder in Installation 04-09-2010
5 10
5
10
ftk
After upgrading to 4.1 no charts display any timestamps on the y axis if the displayed time range exceeds 24 hours. T...
by ftk Motivator in Installation 04-08-2010
0 2
0
2
Ellen
Under Linux Splunk 4.1, I want to install the PDF Report Server and have downloaded the app file from Splunkbase. Whe...
by Ellen Splunk Employee Splunk Employee in Installation 04-08-2010
3 2
3
2
Jaci
In inputs.conf the default host name is set to the fqdn, test-server.foobar.com. But when I search for that host, it ...
by Jaci Splunk Employee Splunk Employee in Getting Data In 04-08-2010
2 5
2
5
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...
Top Karma Authors