All Posts

Find Answers
Ask questions. Get answers. Find technical product solutions from passionate members of the Splunk community.

All Posts

Hi @ITWhisperer  I have already used the finalized and done brackets, but the issue still persists. Additionally, I moved the saved search to the search app location to test, but it did not resolve ... See more...
Hi @ITWhisperer  I have already used the finalized and done brackets, but the issue still persists. Additionally, I moved the saved search to the search app location to test, but it did not resolve the problem either.
Removing the depends will make the time selector input visible, but it still won't work because the change handler uses the operational_start_time token (which as we know is currently available for a... See more...
Removing the depends will make the time selector input visible, but it still won't work because the change handler uses the operational_start_time token (which as we know is currently available for all users).
@ITWhisperer  Sure, thanks for the suggestion. Let me check
Hi @Sundaravarathan  You're correct in that Dashboard Studio does not allow custom CSS/JS as you are currently able to use with Classic XML dashboards, therefore you might be better sticking to your... See more...
Hi @Sundaravarathan  You're correct in that Dashboard Studio does not allow custom CSS/JS as you are currently able to use with Classic XML dashboards, therefore you might be better sticking to your existing setup for your cloud move. From my experience, Cloud migrations should be exactly that - a migration. If you start making too many changes then this becomes a "transformation" rather than a "migration" and it becomes significantly harder to compare your existing workflows/dashboards/alerts etc to your new Splunk Cloud versions and makes the user-acceptance phase of the migration so much harder. I would recommend sticking to your existing dashboards until you have migrated to Splunk Cloud, and then when you are ready iterate over to convert existing classic XML dashboards into Dashboard Studio dashboards based on features available etc.  Did this answer help you? If so, please consider: Adding karma to show it was useful Marking it as the solution if it resolved your issue Commenting if you need any clarification Your feedback encourages the volunteers in this community to continue contributing
Hi @Youn  When a bucket in a SmartStore index rolls to warm, the bucket is copied to S3 remote storage, therefore its only the hot buckets which will be on EBS and *not* on  S3.  What does your arc... See more...
Hi @Youn  When a bucket in a SmartStore index rolls to warm, the bucket is copied to S3 remote storage, therefore its only the hot buckets which will be on EBS and *not* on  S3.  What does your architecture look like? Do you have an indexer cluster? If so you should have a replica bucket on another indexer, so in the event of a failure to an EC2 instance your replica will still exist and when rolled to warm can be uploaded to S3. The following might be useful for you in terms of backup strategy https://cloudian.com/guides/splunk-big-data/splunk-backup-what-are-your-options/#smartstore - Ultimately I'm not sure if the EBS backup gives you something you need, do you have a process around this to enact when you need to rebuild a host?   Did this answer help you? If so, please consider: Adding karma to show it was useful Marking it as the solution if it resolved your issue Commenting if you need any clarification Your feedback encourages the volunteers in this community to continue contributing
Hi @livehybrid/@PrewinThomas  , Yes, The linux server is a VM running on azure. I am checking the access and availability of the file as mentioned. Will let you know once I'm done.  The Splunkd... See more...
Hi @livehybrid/@PrewinThomas  , Yes, The linux server is a VM running on azure. I am checking the access and availability of the file as mentioned. Will let you know once I'm done.  The Splunkd event, 06-13-2025 19:30:53.923 +0000 ERROR AggregatorMiningProcessor [3844932 structuredparsing] - Uncaught exception in Aggregator, skipping an event: Can't open DateParser XML configuration file "/opt/splunkforwarder/etc/datetime.xml": No such file or directory - data_source="/opt/splunkforwarder/var/spool/splunk/tracker.log", data_host="-----", data_sourcetype="splunkd_latency_tracker" 06-13-2025 19:28:30.171 +0000 ERROR ExecProcessor [3844925 ExecProcessor] - message from "/opt/splunkforwarder/etc/apps/pwc_west_ghs_uf_nix_v2/bin/package.sh" /bin/sh: 1: /opt/splunkforwarder/etc/apps/pwc_west_ghs_uf_nix_v2/bin/package.sh: not found 06-13-2025 18:28:29.084 +0000 ERROR ExecProcessor [3844925 ExecProcessor] - message from "/opt/splunkforwarder/etc/apps/pwc_west_ghs_uf_nix_v2/bin/hardware.sh" /bin/sh: 1: /opt/splunkforwarder/etc/apps/pwc_west_ghs_uf_nix_v2/bin/hardware.sh: not found Is possible to narrow down the issue with these events? Thank you.
Studio is still limited in the finer aspects of dashboard control and visualisation. Best practice (in my opinion) at the moment is to stick with Classic Simple XML, especially if you already have a ... See more...
Studio is still limited in the finer aspects of dashboard control and visualisation. Best practice (in my opinion) at the moment is to stick with Classic Simple XML, especially if you already have a working dashboard on-prem, just copy (the source) to Cloud. 
Very sparse information here - please share some anonymised sample events, preferably in a code block (using the </> edit option. Please share what you have already tried. Where your events have been... See more...
Very sparse information here - please share some anonymised sample events, preferably in a code block (using the </> edit option. Please share what you have already tried. Where your events have been ingested to. What your current results are, etc. Contributors are pretty talented here but mind-reading is a rare capability!
Please help share query to check  > network logs and firewall blocks for specific Host machine > LDAP password login failed query for specific user account >
Check the permissions and visibility of all the saved searches, although particularly set_operational_hours as this seems to set the appropriate tokens. You could also try using done rather than fina... See more...
Check the permissions and visibility of all the saved searches, although particularly set_operational_hours as this seems to set the appropriate tokens. You could also try using done rather than finalized
If anyone knows, could you please let me know the following? Our Splunk Enterprise system is based on AWS EC2.We use AWS S3 for Splunk SmartStore.We take backup of EBS and S3(smartstore) everyday.Bu... See more...
If anyone knows, could you please let me know the following? Our Splunk Enterprise system is based on AWS EC2.We use AWS S3 for Splunk SmartStore.We take backup of EBS and S3(smartstore) everyday.But the cost of S3 backup is very high.So we are planning to stop backup of  S3.Because we have Smart S3 versioning turned on. If we had to restore the EC2 , could we restore from S3 versioning? Since the timing of EBS backup and S3 versioning are different, I think there may be a problem if I restore EBS and restore S3 from a previous version at a different slice. Since I want to prioritize cost reduction, it is not a problem if some data on the EBS side is missing as long as it can be read without any problems. Please let me know if you have any ideas on how to reduce backup costs in a similar environment.
Hello Splunk Community,   We are currently transitioning a live dashboard from Splunk Enterprise to Splunk Cloud. The original dashboard was built using HTML, CSS, and JavaScript to monitor three c... See more...
Hello Splunk Community,   We are currently transitioning a live dashboard from Splunk Enterprise to Splunk Cloud. The original dashboard was built using HTML, CSS, and JavaScript to monitor three critical KPIs: Success, Response, and Availability. In our Splunk Enterprise version, we implemented: A custom alarm beep and red colour flash when any KPI drops below 99%. Pagination to manage and display data effectively.   However, while recreating this dashboard in Splunk Cloud Studio, we’ve encountered limitations: It seems that Studio doesn’t support custom pagination features. We're unable to add the alarm beep and visual alerts as we did use HTML/CSS/JS in Enterprise. 3. Federated searches limitation and how we can use for this requirement and how to their license usage Could someone please clarify:  What are the limitations of using HTML, CSS, and JavaScript in Splunk Cloud and Studio dashboards? Are there any workarounds or supported methods to implement these types of visual and audio alerts in Splunk Cloud? Any suggestions or examples on how to handle pagination and threshold-based alerts within Studio? Your insights or best practices would be greatly appreciated.  Thank you in advance for your support!    
Hi @KishoreSrini  I think the collectd and runsvc.sh logs are not Splunk related, these look like they might be associated with VstsAgentService - Is this a VM running on Azure / Azure Pipelines? R... See more...
Hi @KishoreSrini  I think the collectd and runsvc.sh logs are not Splunk related, these look like they might be associated with VstsAgentService - Is this a VM running on Azure / Azure Pipelines? Regarding the Splunk error failed to open file - Can you confirm if the file actually exists in the filesystem? And if so, what events are in the splunkd.log? Are there any warnings/errors? Please could you confirm the ownership on /opt/splunkforwarder/var/log/splunk/splunkd.log and also confirm the user which Splunk is running as: ps -a | grep -i splunk  Did this answer help you? If so, please consider: Adding karma to show it was useful Marking it as the solution if it resolved your issue Commenting if you need any clarification Your feedback encourages the volunteers in this community to continue contributing
No, I am not using a Splunk add-on I am using the Splunk forwarder to send the logs
@KishoreSrini  Can you check if there is any permission issue?  collectd: processmon plugin: Error reading /proc/3605381/stat collectd failed to read process stats, likely because the process with... See more...
@KishoreSrini  Can you check if there is any permission issue?  collectd: processmon plugin: Error reading /proc/3605381/stat collectd failed to read process stats, likely because the process with PID 3605381 ended or permissions were insufficient "/opt/splunkforwarder/var/log/splunk/splunkd.log": No such file or directory - Splunk couldn't access it's main splunkd.log file this also indicates about file unavailablity or permission issue Regards, Prewin Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!
Thank you for your reply. I am using Splunk 9.4.2 which is the latest version as of now.
I am newbie to this env and I'm trying to understand some logs regrading a linux server troubleshoot. A server stopped sending metrics to Splunk (eventlogs are fine). To troubleshoot, I searched the ... See more...
I am newbie to this env and I'm trying to understand some logs regrading a linux server troubleshoot. A server stopped sending metrics to Splunk (eventlogs are fine). To troubleshoot, I searched the error logs on that time stamp. These are the logs I got, 15:02:44.000: collectd[909]: processmon plugin: Error reading /proc/3605381/stat 15:12:53.000: runsvc.sh[968]: Error reported in diagnostic logs. Please examine the log for more details. 15:12:53.000: runsvc.sh[968]: 2025-06-13 19:12:53Z: Agent connect error: The HTTP request timed out after 00:01:00.. Retrying until reconnected. 15:31:07.000: splunk[3844643]: ERROR - Failed opening "/opt/splunkforwarder/var/log/splunk/splunkd.log": No such file or directory Please help to understand the issue and troubleshooting steps for the issue(If possible) Thank you in advance.
Hello @_joe, If it is mentioned on the Splunkbase, then the TA would be compatible with the Splunk version. However, we will need more info on the ERROR log that you're receiving to understand why t... See more...
Hello @_joe, If it is mentioned on the Splunkbase, then the TA would be compatible with the Splunk version. However, we will need more info on the ERROR log that you're receiving to understand why the input won't run.  Check if you can enable the DEBUG logging and what ERROR does the python script log and we can take it from there. Thanks, Tejas.
@ITWhisperer So, if I remove the depends attributes, will it start working for the users?
@bakeery  Are you using sysmon add-on? #https://splunkbase.splunk.com/app/5709 Also refer below #https://community.splunk.com/t5/Getting-Data-In/Why-isn-t-the-Sysmon-Technology-Add-on-Parsing-my... See more...
@bakeery  Are you using sysmon add-on? #https://splunkbase.splunk.com/app/5709 Also refer below #https://community.splunk.com/t5/Getting-Data-In/Why-isn-t-the-Sysmon-Technology-Add-on-Parsing-my-Sysmon-Logs/m-p/370757   Regards, Prewin Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!