Hi Guys,
In my project environment, every splunkd is installed using splunk user. So I need to create an alert if any splunkd on any splunk server (enterprise or UF) gets startedwith root or any o...
...or what settings I should ignore?
To get to the below images i have a saved report and then I go to Settings > Searches, Reports, and Alerts. find the saved report and here is where I can s...
how to calculate job start time and job end time of transaction for particular time and to set trigger mail when start time and stop time?
This is my query ,i am getting two events as start t...
...he "/etc/init.d/splunk" start-up script, but also sometimes even after I manually shut down Splunk with "splunk stop".
What exactly triggers the unclean shutdown warning and the recovery prompt?
W...
I am trying to set up an alert that runs a script after finding a result. For some reason, we see this error each time we try to run the script:
06-01-2020 13:20:09.091 -0500 ERROR M...
...he saved searches, alerts. I even recursively grepped the entire splunk config directory but found nothing defined by this name. I think this is causing issue with search disk quota being exhausted. W...
...anager, but if i schedule that same search but dont make it rt search it does work and I get all my alerts in my inbox.
This problem started after I upgrade to Splunk 5, with Splunk 4.x I didnt have t...
For new RBA users, here are some frequently asked questions to help you better getstartedwith the product. 1. What is RBA(Risk-based Alerting)? Risk-Based Alerting (RBA) is Splunk's m...
Alerts no longer email, however they do show up in triggered alerts. This started sometime yesterday, before that we have been getting email alerts and creating email alerts for months.
var\log\s...
Here the logs I have
04/24/2017 02:42:08 PM
LogName=System
SourceName=Microsoft-Windows-Service Control Manager
EventCode=7036
EventType=4
Type=Information
ComputerName=Mycomputer
TaskCategory=T...