...ime the activity stopped, rather than just stopping back in August. How would I tweak the following query to include the ceased traffic? earliest=05/01/2020:00:00:01 latest=now index=nix s...
Hi Guys,
In my project environment, every splunkd is installed using splunk user. So I need to create an alert if any splunkd on any splunk server (enterprise or UF) gets started with root or any o...
...p to version 8.0.
https://splunkbase.splunk.com/app/833/#/overview
The Nix Add-on description states that it works in tandem with the Nix App. If we were on Splunk Enterprise 7.3, where t...
We currently have our Splunk environment running on Server 2012. I've built out an Hadoop cluster in *NIX and currently building a *NIX box for Hadoop Analytics. Will I be able to roll data from o...
...plunk universal forwarder (nix) UF ---> HF here is my deploymentclient.conf [deployment-client] [target-broker:deploymentServer] #this was part of default after command was run d...
I am looking for an automated way to install Splunk 7.0.2 on CentOS 7 64 bit using the best practices for setting Transparent Huge Pages (THP), ulimit, permissions, ports, and inputs settings.
Hi, I am trying to create a alert for cpu usage by using below query, index=os host=cbtsv | stats latest(*) as * by host | table _time cpu_load_percent cpu_user_percent | eval CPU=cpu_load_per...
Hello,
I recently upgraded Splunk Enterprise (and Heavy Forwarder) instances to 8.2.5 and 8.2.6. Both versions (maybe others too) install the Python Upgrade Readiness App 1.0 as default. Then Splun...
Hello Splunkers,
I need to install Splunk forwarder on my AIX machine. Can someone please share step by step procedure?
Also, I just ended up Untar the package. But I am not able to see Var dir...
Is there a way yo determine if the license has been accepted on a fresh installation or upgrade of a universal forwarder on a *nix machine? A file/line in a file that aren't present until after the l...