My company is currently using splunk to grab all office365 logs. We are currently having issues with teams. I can see most data, When I go to teams call overview I'm unable too see any logs. &n...
Hello,
The Infrastructure overviewin Splunk ITSI shows entities list like active, unstable, inactive and N/A. Can you help me what is reference point for all these status, in our environment it i...
I want to stop all remote logins to a Splunk server. To do this, I added the following to /etc/system/local/server.conf (as documented in https://docs.splunk.com/Documentation/Splunk/8.0.5/Admin/S...
...ssues, and nothing in my configure > services and teams even for my admin user.
Looking in the logs, I see inindex=_internal source=*itsi_migration.log*
that one of the shpeer tried t...
A number of sourcetypes are coming up as status=red because their data_last_time_seen field is "stuck". All of these are coming from the Microsoft Teams Add-on for Splunk. New data is c...
I have about 20 windows hosts and 20 linux hosts which I'd like to collect metrics and logs/events from.
How do I choose between running the app for Splunk app for Windows Infrastructure (with r...
Hi,
I have joined recently as splunk architect. Have been assigned to work on enhancement of monitoring. We have deployed itsi on our environment. Need to know how best to enable monitoring for d...
We just installed ISIT, and we're also using an app for AD object collection (MS Windows AD Objects ). I'm wondering it's it's possible to configure ISIT to use some of that existing AD data a...