Splunk Administration

Splunk Administration
Category Activity
oreoshake
We're upgrading our forwarders and we always get the warning that outputs.conf cannot be migrated. However, simply m...
by oreoshake Communicator in Getting Data In 03-24-2010
0 1
0
1
Alan_Bradley
When we build 2 Splunk indexing servers for High Availablity, 2 Splunk indexing servers may receive the same log data...
by Alan_Bradley Path Finder in Getting Data In 03-24-2010
0 1
0
1
Alan_Bradley
We plan to use Splunk to keep log for several java application including web server like Tomcat. Those application ar...
by Alan_Bradley Path Finder in Getting Data In 03-24-2010
2 1
2
1
Lowell
How do you get splunk to recognize new buckets without restarting splunkd? This makes the process of restoring or mo...
by Lowell Super Champion in Deployment Architecture 03-24-2010
2 2
2
2
hulahoop
Why would there be a gap of logged events in metrics.log between 01-21-2010 15:47:39.421 and 01-22-2010 08:53:28.231 ...
by hulahoop Splunk Employee Splunk Employee in Getting Data In 03-24-2010
0 5
0
5
Glenn
This is related to an earlier question: http://answers.splunk.com/questions/490/why-do-variations-in-sourcetype-appea...
by Glenn Builder in Getting Data In 03-22-2010
2 5
2
5
Alan_Bradley
In my environment we make clones of our linux servers so that we don't have to build out a server from scratch for ev...
by Alan_Bradley Path Finder in Installation 03-20-2010
0 2
0
2
Alan_Bradley
I'm concerned about CLI and REST authentication tokens. How long do those stay valid and is it configurable?
by Alan_Bradley Path Finder in Getting Data In 03-19-2010
2 1
2
1
Alan_Bradley
Are queries that go to two index servers in different time zones handled correctly? I'm assuming it does, but want to...
by Alan_Bradley Path Finder in Getting Data In 03-19-2010
0 1
0
1
Alan_Bradley
WHen I try to install it gives me a message that GLIBC-2.3 is required but there is no support to get this package fo...
by Alan_Bradley Path Finder in Installation 03-19-2010
0 1
0
1
Alan_Bradley
I do not see in any of the manuals or Help how to add host servers. You label the targets as Host on the main page bu...
by Alan_Bradley Path Finder in Getting Data In 03-19-2010
1 1
1
1
hulahoop
If a size- or time-based retention policy is set via maxTotalDataSizeMB or frozenTimePeriodInSecs in indexes.conf, ho...
by hulahoop Splunk Employee Splunk Employee in Getting Data In 03-18-2010
3 2
3
2
oreoshake
We have Splunk as part of our default vm image but we're having some bucket issues. Initially, the time isn't set an...
by oreoshake Communicator in Monitoring Splunk 03-17-2010
2 1
2
1
SteveS
How can I set up Splunk to automatically open troubletickets?
by SteveS Splunk Employee Splunk Employee in Getting Data In 03-15-2010
1 1
1
1
elusive
Installed Splunk on Windows machine and in the task manager I see these two processes running by default. How can I ...
by elusive Splunk Employee Splunk Employee in Getting Data In 03-13-2010
2 2
2
2
Erik_Swan
I notice there is support for fifo's as inputs. Are there any benefits to using a fifo or is it just support for thos...
by Erik_Swan Splunk Employee Splunk Employee in Monitoring Splunk 03-13-2010
1 2
1
2
dskillman
I've reduced the log retention timeout so that the disk footprint doesn't grow. Is there any way to remove anything ...
by dskillman Splunk Employee Splunk Employee in Deployment Architecture 03-13-2010
2 2
2
2
chris
Hi I am trying to filter events on a LightWeightForwarder, but they don't get dropped. Is there a way to debug this?...
by chris Motivator in Getting Data In 03-12-2010
1 4
1
4
Nate_Schmoll
A query to count tag=pci entries by eventtype (and happens to be part of the application): tag=pci | stats count by ...
by Nate_Schmoll Engager in Knowledge Management 03-12-2010
4 5
4
5
oreoshake
I've followed the instructions on http://www.splunk.com/base/Documentation/4.0.9/Developer/DefaultApp to set the defa...
by oreoshake Communicator in Monitoring Splunk 03-10-2010
6 2
6
2
oreoshake
I looked at the report for timestamping errors and found a fair amount of errors. I’ve been following the Splunk blo...
by oreoshake Communicator in Monitoring Splunk 03-10-2010
0 5
0
5
hulahoop
If I have a field value that is URL encoded then base-64 encoded, is it possible to have Splunk decode this field bef...
by hulahoop Splunk Employee Splunk Employee in Getting Data In 03-10-2010
3 7
3
7
Mick
Apart from the fact that a lightforwarder does not have a web UI, what are the main differences between the 2 apps?
by Mick Splunk Employee Splunk Employee in Getting Data In 03-09-2010
0 2
0
2
chris
Hi I have set up a light weight forwarder that appears to be getting data to the indexer. But I can't search for an...
by chris Motivator in Getting Data In 03-05-2010
2 2
2
2
the_wolverine
I'm trying to configure a search Time Window for my Splunk roles. I've read the documentation but can't find instruc...
by the_wolverine Champion in Installation 03-05-2010
1 1
1
1
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...
Top Karma Authors