Seeking advice for how to best backup/restore splunk databases to newly built systems with minimal application downtime for 3 index servers. Current OS - RHEL, to be OS - Oracle Ent Linux.
Current i...
...one system, five messages fromanother (backup) system. Messages from the system use the same SrcMsgId value. Each system has a unique SrcMsgId within the same chain. The message chain from...
We have an SHC cluster on enterprise Version 7.3.5 & ITSI 4.4. Recently we trigged to upgrade our ITSI from 4.4.X to 4.7.0 and it failed.
It was an generic error message and support was not a...
Hi, I want to restorea KVLookup fromabackupsystem , and not from the Splunk backup.
Is there a way to restorea KVLookup file in case I don't have the backup set up in Splunk? Or do I h...
...configurations Basically to back up Splunk, I need to make a copy of "$SPLUNK_HOME/etc/*" and "$SPLUNK_HOME/var/lib/splunk/defaultdb/db/*" (after rotating the hot buckets.) My question is, how is this restore...
...y visiting www.splunk.com.... The search job has failed due to an error. You may be able view the job in the Job Inspector when i check settings->system->licensing and click "s...
We created a KV Store in a search head in clustered architecture, by adding the files collections.conf and transformations.conf.
--But we can't access the kvstore using inputlookup command and g...
...pp), we noticed that the dashboards, reports, and indexes for our app can no longer be deleted from the Splunk Web UI or CLI. The delete button is missing for the dashboards and reports. The button is g...
Im a splunk admin and I got asked to update the inputs.conf file for the app pingfederate. Im a little unsure of how to do it and I figured id ask here instead of bricking our prod system. T...
Hi Folks,
We are planned to upgrade our Splunk 7.2.4 to 8.0.3.
7.2.4 was installed using rpm package.
We are thinking to upgrade using tarball.
Since earlier version is installed using rpm, O...