Hi, I have configured IT Essential Works (4.9.2) with Exchange content pack (1.4.3) and TA-Exchange-ClientAccess (4.0.3). By chance I was checking PowerShell event logs in our exchange s...
The object= line in the inputs.conf for TA-Exchange-2013-ClientAccess doesn't match the throttling-counters search macro. See below:
[perfmon://MSExchange_Throttling]
index=perfmon
object=M...
...aster] We currently are only backing up the index files which is very risky so I need to get the configuration backed up as well. From reading the documents it seems that generally we only n...
Hi everyone, I'm a bit confused about the retention time of an index. I have created an index (via indexes.conf) with 90 days retention time and max volume of 50GB... so, I always knew, that the log...
Hello everyone, I'm a newbie, so please be gentle.
We are using Amazon Linux 2. Our configuration has a Universal Forwarder co-hosted with a Jenkins controller node. The UF is m...
Hi there, Looking into /opt/splunk/etc/system/local/authorize.conf I saw alot of configurations as below. Would like to understand how this came about, and is it of any concern? t...
Hello all, I have what is probably a pretty basic question about configuration files. I know the precedence goes like this: 1. System local directory -- highest priority 2. App l...
I have a Splunk 9.0.4 estate on Windows 2019 with the following: Search head 2 x indexers Cluster master/deployment server I'm trying to automate all deployments of apps to forwarders and all configur...
...ompliant but it wasn't the case as many of them are. Unfortunately, I am running out of ideas and need some help configuring it. Need someone who can help me with it. Thanks much,