Splunk Administration

Splunk Administration
Category Activity
Mick
Apart from the fact that a lightforwarder does not have a web UI, what are the main differences between the 2 apps?
by Mick Splunk Employee Splunk Employee in Getting Data In 03-09-2010
0 2
0
2
chris
Hi I have set up a light weight forwarder that appears to be getting data to the indexer. But I can't search for an...
by chris Motivator in Getting Data In 03-05-2010
2 2
2
2
the_wolverine
I'm trying to configure a search Time Window for my Splunk roles. I've read the documentation but can't find instruc...
by the_wolverine Champion in Installation 03-05-2010
1 1
1
1
Jaci
Seeing this error in splunkd.log on a splunk indexer when running a saved search. What does it mean?
by Jaci Splunk Employee Splunk Employee in Monitoring Splunk 03-01-2010
2 1
2
1
the_wolverine
I'm trying to configure LDAP auth for Splunk. I'm running into an issue where AD is only giving me 1000 entries and ...
by the_wolverine Champion in Security 02-27-2010
2 2
2
2
Scott
In the installation manual it shows how once you have indexed some data by using the "du -shc hot_v*/rawdata" command...
by Scott Engager in Installation 02-23-2010
1 1
1
1
Alan_Bradley
I need to do the following on my forwarder: Forward all data received and gathered by the forwarder to Splunk indexe...
by Alan_Bradley Path Finder in Getting Data In 02-23-2010
1 1
1
1
Justin_Grant
[I heard this question on an internal mailing list, but it seemed generally relevant so asking it here too] I have a...
by Justin_Grant Contributor in Getting Data In 02-22-2010
1 2
1
2
hulahoop
The use of LINE_BREAKER is a bit cryptic to me... ok, a lot. But I think I've managed to figure out how to break my ...
by hulahoop Splunk Employee Splunk Employee in Getting Data In 02-10-2010
0 6
0
6
Alan_Bradley
When I've created a new index. how can I direct certain sourcetypes to be indexed in that new index, rather than into...
by Alan_Bradley Path Finder in Security 02-10-2010
0 1
0
1
hulahoop
What I'm trying to do: at index time, create a multiline event based on a unique ID. In the data sample below, I nee...
by hulahoop Splunk Employee Splunk Employee in Getting Data In 02-08-2010
2 6
2
6
Yancy
Sometimes Splunk sets the sourcetype on an incoming file as breakable_text or too_small. What determines these sourc...
by Yancy Path Finder in Getting Data In 01-29-2010
1 1
1
1
Justin_Grant
I'm trying to use Splunk to monitor both runtime metrics and configuration state of a server application like JBoss o...
by Justin_Grant Contributor in Getting Data In 01-27-2010
2 4
2
4
benstraw
I don't want to restart splunk right now, but the UI is giving my and my users an annoying message saying I need to r...
by benstraw Splunk Employee Splunk Employee in Deployment Architecture 01-27-2010
2 2
2
2
Justin_Grant
I'm thinking about using the DEDUP commend to solve the following problem: I have an event with an ID field and I'd l...
by Justin_Grant Contributor in Monitoring Splunk 01-22-2010
2 1
2
1
Ledio_Ago
Are there ways in Splunk to monitor and index any activity on Windows Registry?
by Ledio_Ago Splunk Employee Splunk Employee in Getting Data In 01-20-2010
2 1
2
1
jrodman
I will have 100GB coming in per day, with an expectation of 20 concurrent users at any given time, with probably arou...
by jrodman Splunk Employee Splunk Employee in Monitoring Splunk 01-20-2010
2 1
2
1
matt
What private key pairs are used to generate the hashed passwords in authentication.conf or the passwd file?
by matt Splunk Employee Splunk Employee in Security 01-15-2010
1 1
1
1
jrodman
I have a directory /logdir and it contains various types of files, such as apache logs, syslog files, local applicati...
by jrodman Splunk Employee Splunk Employee in Getting Data In 01-15-2010
2 1
2
1
matt
What do I need to do to set the correct hostname for an event?
by matt Splunk Employee Splunk Employee in Getting Data In 01-15-2010
2 3
2
3
jrodman
When my selected coldToFrozenScript runs, which can take 10 minutes, the splunk search interface stops working until ...
by jrodman Splunk Employee Splunk Employee in Getting Data In 01-15-2010
0 1
0
1
benstraw
I just installed splunk and indexed a log file with data that is from earlier this year, The summary dashboard shows ...
by benstraw Splunk Employee Splunk Employee in Knowledge Management 01-14-2010
1 1
1
1
matt
If our users navigate to Manager --> Views they can see all the views, but they do not have permissions to edit or ad...
by matt Splunk Employee Splunk Employee in Security 01-14-2010
1 1
1
1
cfrln
I have data indexed but the "all indexed data" dashboard module is empty. Searching for * over all time produces no r...
by cfrln Explorer in Getting Data In 01-14-2010
2 2
2
2
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...
Top Karma Authors