| Thread Info | |||||
|---|---|---|---|---|---|
| 
      
        Hello Everyone, 
  I'm in a bit of a brain pickle right now and hoping the community can help. I have a Linux box wit...
        
       
         
           by 
           
                
                    
                        sheenay
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Enterprise
           
           
              
               10-21-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        hello, splunker
  I have question. plz
  I upgraded 7.0.1 to 8.0.6 but, my uf is 6.4.10 for win7.
  I saw the documen...
        
       
         
           by 
           
                
                    
                        YUNHYEONG
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Enterprise
           
           
              
               10-25-2020
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  5
	 
 | |||
| 
      
        I have a device that set up the syslog to send to Splunk and everything working great.  I can see the syslog in Splun...
        
       
         
           by 
           
                
                    
                        matoulas
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Enterprise
           
           
              
               10-26-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  0
	 
 | |||
| 
      
        The search head that our security team uses is filling up the /opt/splunk/var/lib/splunk/kvstore/. The directory is a...
        
       
         
           by 
           
                
                    
                        jcgever
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Enterprise
           
           
              
               10-26-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  0
	 
 | |||
| 
      
        I've read all the compatibility matrix docs, but I'm not sure how my situation fits into it. Specifically compatibili...
        
       
         
           by 
           
                
                    
                        jdmclemore
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Enterprise
           
           
              
               10-22-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        Splunk upgrade process seems to be very confusing from 7->8.
  I stop splunk using a systemctl splunk stop to stop th...
        
       
         
           by 
           
                
                    
                        gauravmsharma
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Enterprise
           
           
              
               09-14-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  6
	 
 | |||
| 
      
        I am trying to send logs through UF to my Stand alone instance but data is not getting forwarded.
  I have UF install...
        
       
         
           by 
           
                
                    
                        Ashwini008
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Enterprise
           
           
              
               10-23-2020
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        I want to compare one field between two index. For example Field A.
  index A: Field A, Field B, Field C
  index B: F...
        
       
         
           by 
           
                
                    
                        JustAnotherGuy
                    
                
           
             
             
               Observer
             
           
           in
           Splunk Enterprise
           
           
              
               10-23-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        Hello,
  I am trying to create basic roles for my app, the corresponding authorize.conf looks as follows:
  
   # Ind...
        
       
         
           by 
           
                
                    
                        damucka
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Enterprise
           
           
              
               10-21-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Hello,
  I need to create a db output, however when I try to do this the option to choose schema and table are grayed...
        
       
         
           by 
           
                
                    
                        damucka
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Enterprise
           
           
              
               10-23-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  0
	 
 | |||
| 
      
        Hi,
  I have requirement where I have to read data from an email in outlook and index it in splunk.
  Every week afte...
        
       
         
           by 
           
                
                    
                        Ashwini008
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Enterprise
           
           
              
               10-15-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        We   would like to remove EBS volumes which were used for cold store and DM summary Docs is not overly clear on the r...
        
       
         
           by 
           
                
                    
                        rbal_splunk
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Enterprise
           
           
              
               10-22-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Trying to route windows application logs to correct index based on event data. The scenario I have XmlWinEventLogs co...
        
       
         
           by 
           
                
                    
                        sean_aditum
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Enterprise
           
           
              
               09-23-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Hi! I am looking to try to standardize my configuration across my Search Head Cluster. I have 15 Search Heads, and wh...
        
       
         
           by 
           
                
                    
                        skirven
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Enterprise
           
           
              
               10-21-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Hey everyone. I have never tried creating event annotation before so i am not able to grasp it properly. 
  I want to...
        
       
         
           by 
           
                
                    
                        nikitha15
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Enterprise
           
           
              
               06-18-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        What were the new Splunk platform announcements made at .conf20?
        
       
         
           by 
           
                
                    
                        judithsr
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Enterprise
           
           
              
               10-22-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Hi at all, probably it's an already asked question but I cannot find the correct one: I upgraded Splunk to 8.0.2 on m...
        
       
         
           by 
           
                
                    
                        gcusello
                    
                
           
             
             
               SplunkTrust
             
           
           in
           Splunk Enterprise
           
           
              
               02-17-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        I want to know how can I extract show source code from event action type. I tried using _raw and and rex command. I e...
        
       
         
           by 
           
                
                    
                        animeshkmr54
                    
                
           
             
             
               Observer
             
           
           in
           Splunk Enterprise
           
           
              
               10-21-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        Has anyone been able to track "unintended" disconnections from Citrix VDI with Splunk? We have a DB Connection to the...
        
       
         
           by 
           
                
                    
                        Rob_O
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Enterprise
           
           
              
               10-20-2020
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        We have scenario where we run a indexer cluster with 10+ indexers and the Universal Forwarders send data to all these...
        
       
         
           by 
           
                
                    
                        VasukiPramod
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Enterprise
           
           
              
               10-21-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  0
	 
 | |||
| 
      
        In searchhead cluster with six machines, only one SH machine is not giving results for a particular app.
  
   We hav...
        
       
         
           by 
           
                
                    
                        Reethika
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Enterprise
           
           
              
               10-20-2020
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  8
	 
 | |||
| 
      
        hi all,Has anyone able to get the upgrade ufw app for windows to work?  I get a message in the logs saying it started...
        
       
         
           by 
           
                
                    
                        boss6
                    
                
           
             
             
               Loves-to-Learn
             
           
           in
           Splunk Enterprise
           
           
              
               06-15-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Hello plp. At the moment i need to upgrade a bunch  of Ufs (linux and windows), from versions 6 & 7 to 8.0. I have se...
        
       
         
           by 
           
                
                    
                        tinrush1991
                    
                
           
             
             
               Loves-to-Learn Lots
             
           
           in
           Splunk Enterprise
           
           
              
               10-21-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  0
	 
 | |||
| 
      
        Hi guys, I need to configure an alert when people access as root in a server and for that I have two types of events:...
        
       
         
           by 
           
                
                    
                        franciscof
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Enterprise
           
           
              
               10-21-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  0
	 
 | |||
| 
      
        Hi all,
  Does anyone know of any way to update an event in Splunk?
  so far what my searches brought me was reindexi...
        
       
         
           by 
           
                
                    
                        johnsynack
                    
                
           
             
             
               Loves-to-Learn
             
           
           in
           Splunk Enterprise
           
           
              
               10-20-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 |