Is there a way to monitor the searches for some specific fields? Let's say I wish to monitor if anyone is running any query that returns my SSN in the results.
When I click the Indexes and Volumes>volume_detail_instance,the page has no data to display,and it tips 'Search is waiting to type'. Anyone who can help me solve this problem,t...
Hi to all,
I have three machines: 1 deployment-server, 1 SH/Indexer and 1 forwarder. Looking at "monitoring console-panoramics" on deployment-server, i don't see the correct configuration (is a...
Hello Team, Splunk UF has been installed in all our 1000+ windows servers and we are monitoring those logs. Now the scenario is we have one more Splunk team in my organization and they needs t...
...se as a syslog and audit log store similar to how ELK is often used. While we will add additional data sources at some point my primary focus is on collecting and forwarding /var/log/audit/a...
Hello,
How would I initialize monitor command to pull the data/files from variable paths /locations? Some examples along with monitor command provided below:
Paths/Locations:
/RTAM/P...
Hi Team,
I've multiple monitors on multiple forwarders and multiple tcpouts, I need to use forwarder hostname to route the monitor to respective tcpout, is there a configuration which can p...
...as a lag by 1 or 2 hours based on that country's time zone and Splunk time zone, then figured out the it is because Splunk looks for a timestamp in the event and parse the data. Now , I need to monitor...
We use Kubernetes, and I'd like to use Splunk to get more granular insight into how we use them. Do you have any best practices or apps and add-ons I can use?