Is there any recommended settings for file permissions of .conf files in deployment apps?
For example, I am looking at a deployment app I created using the GUI, and I see in the local folder:
...
So here is my search
index=someindex sourcetype=somesourcetype source="someloglocation*" eventtype="nix_kernel_attached" "\"outcome\":\"success\""
| multikv
| mvexpand _raw
| rex field=_raw "\"u...
It appears that the built in ps_sos.sh and ps_lsof.sh scripts do not output any data on AIX.
Are the scripts any different from the ones that come with the * NIX app? Could the * NIX app s...
Hi everyone!
i logged into my search head and found that the main indexer was at 98% of the total capacity. So i started to look for which host/sourcetype was causing this. I found the search hea...
Is there CIM for Software? I have different sources. ePO, ACAS, Windows add-on, and NIX add-on. Would like to using data model from CIM if possible? Here are the CIM I've already l...
Hello, I am trying to timechart two event types ONLY: heartbeat and start. However, every event in our Splunk is also mapped as nix-all-logs and few other events by the system admin. A...
I'm very new to this and found we do not have any alerts setup for basic things like Disk space on drives etc, I've done some basic courses but I don't know what to put after Host= to capture all dri...
We're in the process of buying another indexing server and my company is set on installing Windows OS on this server. I'm strongly opposed to this as Linux is much easier to use and more reliable. Wh...
...plunk as splunk per best practice. sh, 2 indexers, 1 uf
I could use some pointers on how to properly deal with Linux TA nix with respects to permissions. The source of my problem could be how I'm e...
Any reason why this can't be visualized in a geo cluster map? source="udp:514" index="syslog" NOT src_ip IN (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 17.0.0.0/8) action=DROP src_ip!="162.159.192.9...