Splunk Administration

Splunk Administration
Category Activity
hulahoop
Would someone confirm the following observations regarding data input configuration via inputs.conf? when using wild...
by hulahoop Splunk Employee Splunk Employee in Getting Data In 04-13-2010
0 3
0
3
mudricd
Hi, I have syslog_ng server (sles 10). Everything is logged in this way: /var/log/HOSTS/xx-yy/hostname or ip/log fi...
by mudricd Explorer in Getting Data In 04-13-2010
0 2
0
2
jrich523
I just installed Splunk 4.1 (configured to run on system accounts) and the first thing i did was add an input monitor...
by jrich523 Path Finder in Getting Data In 04-12-2010
1 1
1
1
matt
I need to figure out what LDAP values I should be using to make auth work.
by matt Splunk Employee Splunk Employee in Security 04-12-2010
1 3
1
3
Lowell
Does anyone know if alwaysOpenFile still works in inputs.conf as of Splunk 4.1. It still shows up in the 4.1 docs, b...
by Lowell Super Champion in Getting Data In 04-12-2010
1 6
1
6
dskillman
I have a file with ~6M events that gets FTP'd to Splunk on a daily basis. Unfortunately I don't have control of the ...
by dskillman Splunk Employee Splunk Employee in Getting Data In 04-12-2010
1 1
1
1
Alan_Bradley
What is the mechanism for federating credentials between splunk servers when doing a distributed search?
by Alan_Bradley Path Finder in Security 04-11-2010
1 2
1
2
Alan_Bradley
I'd like to convert a busy server with a bunch of users from default auth to LDAP. How can I do so without losing any...
by Alan_Bradley Path Finder in Security 04-11-2010
1 3
1
3
jsondheimer
I am using Splunk to collect data from the security logs on my network. How long does Splunk store the data that it c...
by jsondheimer New Member in Getting Data In 04-09-2010
0 2
0
2
the_wolverine
I have an instance that I've set up to only run summary searches. Essentially, its a search head but no users connec...
by the_wolverine Champion in Knowledge Management 04-09-2010
0 1
0
1
Steve_G_
For example, does Splunk ignore server.conf, distsearch.conf, or any other conf files if they're located in an apps d...
by Steve_G_ Splunk Employee Splunk Employee in Installation 04-09-2010
2 2
2
2
Alan_Bradley
I just upgraded my install to 4.1 and LDAP auth is no longer working. The failsafe user is all I can use. Previousl...
by Alan_Bradley Path Finder in Installation 04-09-2010
5 10
5
10
ftk
After upgrading to 4.1 no charts display any timestamps on the y axis if the displayed time range exceeds 24 hours. T...
by ftk Motivator in Installation 04-08-2010
0 2
0
2
Ellen
Under Linux Splunk 4.1, I want to install the PDF Report Server and have downloaded the app file from Splunkbase. Whe...
by Ellen Splunk Employee Splunk Employee in Installation 04-08-2010
3 2
3
2
Jaci
In inputs.conf the default host name is set to the fqdn, test-server.foobar.com. But when I search for that host, it ...
by Jaci Splunk Employee Splunk Employee in Getting Data In 04-08-2010
2 5
2
5
rnutting24
Hi, I just created a new app and wanted to point my network inputs to another index, managed by my app. So, I modif...
by rnutting24 Engager in Getting Data In 04-08-2010
1 3
1
3
bwooden
On a Solaris machine, I modified $SLUNK_HOME/etc/system/local/web.conf to use httpport = 80 The below error was then ...
by bwooden Splunk Employee Splunk Employee in Security 04-08-2010
4 5
4
5
the_wolverine
Is there a splunk command or REST endpoint to see the tailing status of monitored files?
by the_wolverine Champion in Getting Data In 04-08-2010
4 2
4
2
MikeyG
Search is index="_internal" source="*metrics.log" group="queue" | timechart perc90(current_size) by name Results are...
by MikeyG Explorer in Getting Data In 04-07-2010
2 3
2
3
Mick
I'm trying to index a file on a mapped network drive, but I keep getting seeing 'Access is denied' in splunkd.log. I...
by Mick Splunk Employee Splunk Employee in Getting Data In 04-07-2010
4 1
4
1
Mick
I just upgraded to version 4.1 and I'm seeing this message in the UI. My minimum free disk space is 1GB and I haven'...
by Mick Splunk Employee Splunk Employee in Monitoring Splunk 04-07-2010
2 1
2
1
rogerssoftware
On my old setup I had all syslogs going to syslog on the Splunk server, but now I'm doing a fresh setup with Ubuntu 9...
by rogerssoftware Explorer in Getting Data In 04-07-2010
1 4
1
4
Alan_Bradley
Splunk is running behind a webserver proxy. Splunk has the following config in web.conf: root_endpoint = /splunk T...
by Alan_Bradley Path Finder in Security 04-07-2010
1 1
1
1
the_wolverine
I have a bunch of Lightweight Forwarders (LWF) forwarding to my central indexer. What happens to my events when the...
by the_wolverine Champion in Getting Data In 04-06-2010
3 4
3
4
Alan_Bradley
I've just upgraded to 4.1 and now I'm getting an error when I search saying: The lookup table 'sid_lookup' does not ...
by Alan_Bradley Path Finder in Getting Data In 04-06-2010
3 7
3
7
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Splunk Asynchronous Forwarding Explained

Splunk asynchronous forwarding is often misunderstood as simply setting autoLBVolume. That is not quite right. ...

55 Days to Go: Secure Your Seat at Splunk University in Denver

Your .conf26 Experience Starts Before Opening Keynote  If Denver is known for its mile-high elevation, Splunk ...

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...
Top Karma Authors