Good morning fellow Splunkers, I am wondering what the caller=init_roll is and if someone could point me to some documentation about it, as I haven't found any yet. Basically, I changed the m...
...Add-on for Nagios" documentation. And i would like to have an overview about what is best to monitor using Nagios and what with Splunk self monitoring. I would appreciate iIf you can p...
...bsp; index="_internal" sourcetype="splunkd_ui_access" servicesNS file!="notify" method=POST As you can see from above this would pick up changes made ONLY through the GUI but how about the C...
...mount of events which are forwarded by the forwarder index=_internal component=Metrics host=APP01 series=* NOT series IN (main) group=per_index_thruput | stats sum(ev) AS eventcount by s...
We have Network outages at times that make the FWs not available. I know that data can get quede up. But what if the outages is long & what does one do to make sure the SOC & IR have the late...
Hi all, in splunk there is always this icon next to your user for the "Health of Splunk Deployment". You can change these indicators and futures or their teshholds, but I can't find anything about...
Hello, I have question about [thruput] setting on UF and internal Splunk log: I did some tests with Splunk UF - I needed to simulate a problem with the tcpout queue and therefore I reduced the v...
Hello everyone! I'm new to splunk, but I'd like to monitory my Splunk Enterprise instance with prometheus and grafana. I'd like to get system statistics about how many messages are ingested by the splunk...
Hi all,
we are having a little trouble finding the cause of the active universal forwarder status changing to disappear and become active again. We have also checked from the network side and there...
How do I increase the number of lines per reports generated by data mapping from say 8000 to 40,000. The reports I get have about 8,000 & I would like o increase this number