...EnterpriseSecuritySuite) from etc/shcluster/apps to etc/apps folder Ran the upgrade command – (/opt/splunk/bin/splunk install app ./splunk-enterprise-security_620.spl -update 1) Ran the essinstall command as per the i...
...mail, the email is not being sent, because the server specified in general mailserver setting is not taken by EnterpriseSecurity Notable Events. Do I need to configure some extra settingsforSplunk...
...nstallation with a machine with indexer and SH role, so I need to remove all activities of the SH and move them to the new machine. Is there any documentation on performing such task? The SH also contains Enterprise...
...cans tsidx files for the search keywords and uses their location references to retrieve from the rawdata file the events to which those keywords refer. SplunkEnterprise creates a separate set...
I'm a Splunk administrator, not a Windows administrator, so my Windows knowledge is limited. Nonetheless, many teams can benefit from having Windows Event Log data in Splunk. What are the best p...
I need details about what to check before I upgrade so I know if my deployment is ready to upgrade. What do I monitor, and how do I benchmark system health before the upgrade?
I'm a Splunk administrator, not a Windows administrator, so my Windows knowledge is limited. Nonetheless, a many teams can benefit from having Windows performance data in Splunk. Is there a best p...
Hi there,
Just noticed that the Notable Event Suppressions page in SplunkEnterpriseSecurity (Configure --> Incident Management --> Notable Event Suppressions) is only showing 30 out of o...
Hi Team,
I have a brand new Splunk implementation. Both SH Cluster and IX Cluster are setup and supported by a Deployer and Cluster Master respectively. The SH Cluster is forwarding all data to t...