Splunk Administration

Splunk Administration
Category Activity
maverick
I have lots of hosts in my environment, but I only want to search across a few of them from time to time. Can I someh...
by maverick Splunk Employee Splunk Employee in Getting Data In 03-31-2010
1 2
1
2
Mick
Some of our servers are running low on Disk capacity and we are concerned with splunk log files generated and stored ...
by Mick Splunk Employee Splunk Employee in Monitoring Splunk 03-30-2010
7 2
7
2
matt_1
We have an global application hosted within a VM environment feeding a common Splunk index server. However the serve...
by matt_1 Explorer in Getting Data In 03-30-2010
0 2
0
2
oreoshake
Everytime I run a splunk command on windows 7, the command runs in a separate window and closes before I can see what...
by oreoshake Communicator in Getting Data In 03-29-2010
1 2
1
2
Simon
Hi folks I've got a distributed deployment and want to keep the overhead on the splunk forwarders as small as possib...
by Simon Contributor in Deployment Architecture 03-29-2010
1 2
1
2
Starlette
Hai There, I am dealing with a forwarder to indexer which is reading a kiwi directory with several types of devices....
by Starlette Contributor in Getting Data In 03-29-2010
1 2
1
2
Michael_Wilde
Does a sinkhole work on all types of forwarders?
by Michael_Wilde Splunk Employee Splunk Employee in Getting Data In 03-29-2010
3 1
3
1
BunnyHop
What should I attach to my install script if I want to start monitoring the event log in "tail" mode. I don't want t...
by BunnyHop Contributor in Installation 03-27-2010
1 7
1
7
zliu
How to disable hostname chaining? Splunk picks the chained hostname rather than the original.
by zliu Splunk Employee Splunk Employee in Getting Data In 03-26-2010
0 1
0
1
Alan_Bradley
I have a light forwarder (v4.0.7) I want to change this to a forwarder instead of a light forwarder. The reason being...
by Alan_Bradley Path Finder in Getting Data In 03-26-2010
0 3
0
3
BunnyHop
Where can I find the log for the bucket activities? I want to troubleshoot on when Splunk checks bucket sizes and wh...
by BunnyHop Contributor in Deployment Architecture 03-26-2010
1 2
1
2
oreoshake
We're upgrading our forwarders and we always get the warning that outputs.conf cannot be migrated. However, simply m...
by oreoshake Communicator in Getting Data In 03-24-2010
0 1
0
1
Alan_Bradley
When we build 2 Splunk indexing servers for High Availablity, 2 Splunk indexing servers may receive the same log data...
by Alan_Bradley Path Finder in Getting Data In 03-24-2010
0 1
0
1
Alan_Bradley
We plan to use Splunk to keep log for several java application including web server like Tomcat. Those application ar...
by Alan_Bradley Path Finder in Getting Data In 03-24-2010
2 1
2
1
Lowell
How do you get splunk to recognize new buckets without restarting splunkd? This makes the process of restoring or mo...
by Lowell Super Champion in Deployment Architecture 03-24-2010
2 2
2
2
hulahoop
Why would there be a gap of logged events in metrics.log between 01-21-2010 15:47:39.421 and 01-22-2010 08:53:28.231 ...
by hulahoop Splunk Employee Splunk Employee in Getting Data In 03-24-2010
0 5
0
5
Glenn
This is related to an earlier question: http://answers.splunk.com/questions/490/why-do-variations-in-sourcetype-appea...
by Glenn Builder in Getting Data In 03-22-2010
2 5
2
5
Alan_Bradley
In my environment we make clones of our linux servers so that we don't have to build out a server from scratch for ev...
by Alan_Bradley Path Finder in Installation 03-20-2010
0 2
0
2
Alan_Bradley
I'm concerned about CLI and REST authentication tokens. How long do those stay valid and is it configurable?
by Alan_Bradley Path Finder in Getting Data In 03-19-2010
2 1
2
1
Alan_Bradley
Are queries that go to two index servers in different time zones handled correctly? I'm assuming it does, but want to...
by Alan_Bradley Path Finder in Getting Data In 03-19-2010
0 1
0
1
Alan_Bradley
WHen I try to install it gives me a message that GLIBC-2.3 is required but there is no support to get this package fo...
by Alan_Bradley Path Finder in Installation 03-19-2010
0 1
0
1
Alan_Bradley
I do not see in any of the manuals or Help how to add host servers. You label the targets as Host on the main page bu...
by Alan_Bradley Path Finder in Getting Data In 03-19-2010
1 1
1
1
hulahoop
If a size- or time-based retention policy is set via maxTotalDataSizeMB or frozenTimePeriodInSecs in indexes.conf, ho...
by hulahoop Splunk Employee Splunk Employee in Getting Data In 03-18-2010
3 2
3
2
oreoshake
We have Splunk as part of our default vm image but we're having some bucket issues. Initially, the time isn't set an...
by oreoshake Communicator in Monitoring Splunk 03-17-2010
2 1
2
1
SteveS
How can I set up Splunk to automatically open troubletickets?
by SteveS Splunk Employee Splunk Employee in Getting Data In 03-15-2010
1 1
1
1
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...
Top Karma Authors