Splunk Administration

Splunk Administration
Category Activity
elusive
Installed Splunk on Windows machine and in the task manager I see these two processes running by default. How can I ...
by elusive Splunk Employee Splunk Employee in Getting Data In 03-13-2010
2 2
2
2
Erik_Swan
I notice there is support for fifo's as inputs. Are there any benefits to using a fifo or is it just support for thos...
by Erik_Swan Splunk Employee Splunk Employee in Monitoring Splunk 03-13-2010
1 2
1
2
dskillman
I've reduced the log retention timeout so that the disk footprint doesn't grow. Is there any way to remove anything ...
by dskillman Splunk Employee Splunk Employee in Deployment Architecture 03-13-2010
2 2
2
2
chris
Hi I am trying to filter events on a LightWeightForwarder, but they don't get dropped. Is there a way to debug this?...
by chris Motivator in Getting Data In 03-12-2010
1 4
1
4
Nate_Schmoll
A query to count tag=pci entries by eventtype (and happens to be part of the application): tag=pci | stats count by ...
by Nate_Schmoll Engager in Knowledge Management 03-12-2010
4 5
4
5
oreoshake
I've followed the instructions on http://www.splunk.com/base/Documentation/4.0.9/Developer/DefaultApp to set the defa...
by oreoshake Communicator in Monitoring Splunk 03-10-2010
6 2
6
2
oreoshake
I looked at the report for timestamping errors and found a fair amount of errors. I’ve been following the Splunk blo...
by oreoshake Communicator in Monitoring Splunk 03-10-2010
0 5
0
5
hulahoop
If I have a field value that is URL encoded then base-64 encoded, is it possible to have Splunk decode this field bef...
by hulahoop Splunk Employee Splunk Employee in Getting Data In 03-10-2010
3 7
3
7
Mick
Apart from the fact that a lightforwarder does not have a web UI, what are the main differences between the 2 apps?
by Mick Splunk Employee Splunk Employee in Getting Data In 03-09-2010
0 2
0
2
chris
Hi I have set up a light weight forwarder that appears to be getting data to the indexer. But I can't search for an...
by chris Motivator in Getting Data In 03-05-2010
2 2
2
2
the_wolverine
I'm trying to configure a search Time Window for my Splunk roles. I've read the documentation but can't find instruc...
by the_wolverine Champion in Installation 03-05-2010
1 1
1
1
Jaci
Seeing this error in splunkd.log on a splunk indexer when running a saved search. What does it mean?
by Jaci Splunk Employee Splunk Employee in Monitoring Splunk 03-01-2010
2 1
2
1
the_wolverine
I'm trying to configure LDAP auth for Splunk. I'm running into an issue where AD is only giving me 1000 entries and ...
by the_wolverine Champion in Security 02-27-2010
2 2
2
2
Scott
In the installation manual it shows how once you have indexed some data by using the "du -shc hot_v*/rawdata" command...
by Scott Engager in Installation 02-23-2010
1 1
1
1
Alan_Bradley
I need to do the following on my forwarder: Forward all data received and gathered by the forwarder to Splunk indexe...
by Alan_Bradley Path Finder in Getting Data In 02-23-2010
1 1
1
1
Justin_Grant
[I heard this question on an internal mailing list, but it seemed generally relevant so asking it here too] I have a...
by Justin_Grant Contributor in Getting Data In 02-22-2010
1 2
1
2
hulahoop
The use of LINE_BREAKER is a bit cryptic to me... ok, a lot. But I think I've managed to figure out how to break my ...
by hulahoop Splunk Employee Splunk Employee in Getting Data In 02-10-2010
0 6
0
6
Alan_Bradley
When I've created a new index. how can I direct certain sourcetypes to be indexed in that new index, rather than into...
by Alan_Bradley Path Finder in Security 02-10-2010
0 1
0
1
hulahoop
What I'm trying to do: at index time, create a multiline event based on a unique ID. In the data sample below, I nee...
by hulahoop Splunk Employee Splunk Employee in Getting Data In 02-08-2010
2 6
2
6
Yancy
Sometimes Splunk sets the sourcetype on an incoming file as breakable_text or too_small. What determines these sourc...
by Yancy Path Finder in Getting Data In 01-29-2010
1 1
1
1
Justin_Grant
I'm trying to use Splunk to monitor both runtime metrics and configuration state of a server application like JBoss o...
by Justin_Grant Contributor in Getting Data In 01-27-2010
2 4
2
4
benstraw
I don't want to restart splunk right now, but the UI is giving my and my users an annoying message saying I need to r...
by benstraw Splunk Employee Splunk Employee in Deployment Architecture 01-27-2010
2 2
2
2
Justin_Grant
I'm thinking about using the DEDUP commend to solve the following problem: I have an event with an ID field and I'd l...
by Justin_Grant Contributor in Monitoring Splunk 01-22-2010
2 1
2
1
Ledio_Ago
Are there ways in Splunk to monitor and index any activity on Windows Registry?
by Ledio_Ago Splunk Employee Splunk Employee in Getting Data In 01-20-2010
2 1
2
1
jrodman
I will have 100GB coming in per day, with an expectation of 20 concurrent users at any given time, with probably arou...
by jrodman Splunk Employee Splunk Employee in Monitoring Splunk 01-20-2010
2 1
2
1
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...
Top Karma Authors