Hi Guys,
am trying to configureSplunk to send me alerts through mobile when the requests against my web server are more than a specified value
i ran the search and it shows me the requests n...
My server has 2 IP addresses and i need to bind the splunkweb to 1 IP and the splunk daemon to the other IP address.
i configure the server.socket_host setting in web.conf.
the splunkweb i...
I'm doing a project to detect click fraud. I created several extractions to take out the IP address, Web Request from that IP address, and the Browser they used from multiple indexes within Splunk. I...
My freshly installed splunk server has by default listening enabled on port 9997.
When I try to configure a universal forwarder, usingsplunk add forward-server ip:9997 , I'm getting a "Login f...
...ful info that I can see.
Another strange thing is the warning on the search head lists an IP value that does not exist for this new indexer, and I have no idea where it got that IP from (server IP s...
...his correct?
Do I have to put the statement disabled = 0 or is it implied?
I haven’t configured anything through Splunkweb, do I need to do that?
Where do I save the inputs.conf file? On t...
...n the forwarder I have inputs set to a log file, and outputs set to the Splunk Enterprise Server.
I have attempted to (via the web interface and the cli) to configure a "receiver" to everyone's f...
...ccess the web server?
If so, where do I configure that?
If not, how do I make the web server accessible to the InterMapper app in Splunk?
We have 3 InterMapper servers, each operating its own web...
We are attempting to configure SSO on our instance of Splunk to allowusers to enter the Splunk app through our own product application (i.e., a button inside our application that will instantiate a...
We are using Apache HTTP to proxy to Splunk. The short version is that we extract creds and put them in the "Remote-User" header. I can provide more complete info if it might help.
Through Splunk...