...warders I've found HERE how to migrate a SplunkEnterprise instance from one physical machine to another, can anybody confirm me the following procedure? - Stop SplunkEnterprise services on the h...
I have defined stacked bar chart in my SplunkEnterprise Dashboard. I've been trying to solve this problem but I cannot solve them.. 😕 Please help me out. These are the problems that I e...
Hi All, I've been exploring various documentation and tutorials, but I'd love to hear from those who have hands-on experience. What are the best practices and recommended steps forconfiguring K...
Good Morning All,
I'm having a hard time moving the entire C:\Program Files\Splunk folder to a new system. I've seen the "guide" online but it just says move the Splunk Home folder. I...
At my current position, I took over for someone who didn't take care of Splunk & Enterprise Security. It looked as if it was never configured fully (Just ran through the little beginning w...
Hello Splunkers! I've encountered challenges while attempting to connect Notion logs to our Splunk instance. Here's what I've tried: Inserting the HEC URL with a public IP on our Splunk on-p...
Hi, I'm using a splunkenterprise based in a docker image, the dashboard is getting all the default windows events but isn't getting sysmon events, I've created the inputs.conf file in t...
...Firehose Nozzle in OpsMan and configured it to talk to HEC ( Step-1) . During this setup , I've enabled HttpEventType: cf:logmessage. By this I see platform metrics on my indexer ( like gorouter e...
...EBUG events to the appropriate index, which is configured to erase them after 1 month. (while other logs are archived)
- the second one is for the extraction of more readable source names.
I've t...
I'veconfigured inputs.conf like below, but I can't see any data. (Other stanzas for [perfmon:// are all working perfectly.)
Splunk Version: SplunkEnterprise 6.2.1
Target Server: Windows 2008 R...