...onitor input stanza.
Without crcSalt Indexer is not reading this file.
We have setretirementandarchivingpolicyas 3 months for all splunk data. So after 3 months will splunk automatically read t...
...oldtofrozendir = $SPLUNK_DB/defaultdb/frozendb frozentimeperiodinsecs = 1209600
According to the "Setaretirementandarchivingpolicy" and "indexes.conf" documentation on splunk docs, the settings i...
My instance of Splunk currently has 9.4 TB of disk for indexing. We have 360GB per day being indexed and I can't increase the disk size to support this daily indexing.
I need to clean up indexed e...
Hi,
We have enabled Application for EUM Browser Monitoring but we are not able to see the data from the Controller UI. We have checked the code snippet for javascript agent that is defined and i...
I wanted to know if I am getting the data from some stream say TCP stream, where is the data stored? As I understand the data gets uploaded and indexed but some day can I get that data from Splunk? o...
...o convert the days to minutes value and then use that in abucket configuration. But I didn't find any proper example in Splunk.
Can anyone help me on this or any good documentation with a proper e...
Where and how can I set the data retention on Splunk?
Because I have seen there are many bow to set it like telemetry, main etc..
So it's really not clear...
...ommand line :
./splunk clean eventdata -f
and I have tried to erase all my log from the splunk folder, but I have still the same problem.
Please can someone help me?