Splunk Administration

Splunk Administration
Category Activity
rnutting24
Hi, I just created a new app and wanted to point my network inputs to another index, managed by my app. So, I modif...
by rnutting24 Engager in Getting Data In 04-08-2010
1 3
1
3
bwooden
On a Solaris machine, I modified $SLUNK_HOME/etc/system/local/web.conf to use httpport = 80 The below error was then ...
by bwooden Splunk Employee Splunk Employee in Security 04-08-2010
4 5
4
5
the_wolverine
Is there a splunk command or REST endpoint to see the tailing status of monitored files?
by the_wolverine Champion in Getting Data In 04-08-2010
4 2
4
2
MikeyG
Search is index="_internal" source="*metrics.log" group="queue" | timechart perc90(current_size) by name Results are...
by MikeyG Explorer in Getting Data In 04-07-2010
2 3
2
3
Mick
I'm trying to index a file on a mapped network drive, but I keep getting seeing 'Access is denied' in splunkd.log. I...
by Mick Splunk Employee Splunk Employee in Getting Data In 04-07-2010
4 1
4
1
Mick
I just upgraded to version 4.1 and I'm seeing this message in the UI. My minimum free disk space is 1GB and I haven'...
by Mick Splunk Employee Splunk Employee in Monitoring Splunk 04-07-2010
2 1
2
1
rogerssoftware
On my old setup I had all syslogs going to syslog on the Splunk server, but now I'm doing a fresh setup with Ubuntu 9...
by rogerssoftware Explorer in Getting Data In 04-07-2010
1 4
1
4
Alan_Bradley
Splunk is running behind a webserver proxy. Splunk has the following config in web.conf: root_endpoint = /splunk T...
by Alan_Bradley Path Finder in Security 04-07-2010
1 1
1
1
the_wolverine
I have a bunch of Lightweight Forwarders (LWF) forwarding to my central indexer. What happens to my events when the...
by the_wolverine Champion in Getting Data In 04-06-2010
3 4
3
4
Alan_Bradley
I've just upgraded to 4.1 and now I'm getting an error when I search saying: The lookup table 'sid_lookup' does not ...
by Alan_Bradley Path Finder in Getting Data In 04-06-2010
3 7
3
7
cdavidy
How do I go about configuring splunk forwarders running on Linux to forward to a specific index for Linux-related inf...
by cdavidy Explorer in Getting Data In 04-06-2010
5 2
5
2
BunnyHop
If the script to roll the hotDB to the warmDB is "| debug cmd=roll index=main", would there be one for rolling the wa...
by BunnyHop Contributor in Getting Data In 04-06-2010
4 2
4
2
zscgeek
Are there are any critical changes to be aware of when migrating a complex distributed scripted auth setup on 3.4.x t...
by zscgeek Path Finder in Deployment Architecture 04-06-2010
1 3
1
3
thepocketwade
In my office we have a script on our log servers that monitors the hosts sending logs and alerts us if a machine star...
by thepocketwade Path Finder in Getting Data In 04-05-2010
0 4
0
4
oreoshake
I'm in the process of migrating to new hardware for my indexers. The easiest way to do this would be: Setup new ind...
by oreoshake Communicator in Installation 04-05-2010
2 3
2
3
Alan_Bradley
I just upgraded from 4.0 to 4.1 and am seeing messages that the indexprocessor was not initialized on startup. How c...
by Alan_Bradley Path Finder in Installation 04-05-2010
2 1
2
1
Justin_Grant
How many tags can be created before Splunk's performance is adversely affected? And what specifcally is adversely af...
by Justin_Grant Contributor in Monitoring Splunk 04-05-2010
3 4
3
4
oreoshake
All of my events show up with gid=-1,uid=-1. Is this a bug or am I doing something wrong?
by oreoshake Communicator in Getting Data In 04-05-2010
1 3
1
3
the_wolverine
I'm trying to set up LDAP authentication and need some assistance. Where do I go for assistance?
by the_wolverine Champion in Security 04-05-2010
2 1
2
1
oreoshake
Any idea how to create a search that finds hosts that are sending BOTH syslog and splunkd traffic? We'd like to turn...
by oreoshake Communicator in Installation 04-05-2010
1 2
1
2
oreoshake
When uninstalling an app, the following errors are preventing splunkd for restarting: 03-30-2010 22:28:12.157 WARN ...
by oreoshake Communicator in Deployment Architecture 04-04-2010
1 2
1
2
Lowell
How do you force the creation of the merged_lexicon.lex for a bucket that was manually restored? (And is this possib...
by Lowell Super Champion in Deployment Architecture 04-03-2010
0 4
0
4
oreoshake
UPDATE: This appears to be a bug specifically related to 4.0.10. The following is a work around in system/local/inp...
by oreoshake Communicator in Getting Data In 04-03-2010
1 3
1
3
the_wolverine
I need some help with figuring out some potential blocked queues. What searches can be run to help me figure this ou...
by the_wolverine Champion in Monitoring Splunk 04-02-2010
0 2
0
2
Chris_R_
My filesystem is full and splunk wont start. How do i make some last minute filesystem space and start splunk? What a...
by Chris_R_ Splunk Employee Splunk Employee in Deployment Architecture 04-02-2010
3 2
3
2
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...
Top Karma Authors