...pecifically for indexers, the documentation states:
"If the indexer is also a *nix host and you want to collect *nix data from it, complete the procedure at Enable the data and scripted inputs within the S...
Hi All, As indicated here (https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-monitor-SPLUNK-HOME-var-log-splunk-audit-log/m-p/506185#M86203), I have been able to get the audit.log f...
I'm trying to set up .log file monitoring so splunk would pull the context of the .log files in to the indexer and nothing i try seems to work.....
Can someone please help? I'm a newbie at this who...
Not working SEDCMD in my props.conf /opt/splunk/etc/system/local/props.conf [ActiveDirectory] SEDCMD-mask_ms_pwd = s/(ms-Mcs-AdmPwd\s*=)\s*.*/ms-Mcs-AdmPwd=*******/ &nb...
Hi,
I would like to ask if the CSV file that is being referenced to in the search command can be from any directory in the machine or must it be within the Splunk folder?
...hat of the subsearch. Based on this behavior I created a workflow that uses my ET2.
When I installed the *NIX app on my searchhead, a few of the global eventtypes started getting applied to my r...
I have an existing Splunk Forwarder currently forwarding data to an indexer.
I have a new deployment server I want to connect Splunk Forwarder to as deployment client.
Should I need to know any...
Is there any way to find out which user/service account is running the splunk services on linux?
I am looking to collect this information from all the forwarders (deployed on servers owned by diff...
...he settings>data inputs>local inputs>files and directories.
If you look at the last line, it indicates it is monitoring /var/log/secure, has source type linux_secure, and app is SA-nix. I...