Hey guys I've been having trouble finding documentation about removing indexed data. After looking through the "meta woot!" app I saw my hosts were growing a few thousand a day and my estreamer app ...
I upgraded from 4.2.2 to 4.2.3 (Windows). After the upgrade, this message appears in the top of my browser:
Misconfigured view 'search_ui_activity' - Unknown parameter 'suppressionList' is d...
Hello everyone,
I know it's possible to remove things from Splunk search that are older than two years, for example. If I apply this setting, space is not freed on the system disk where S...
...ore importantly: How do we recover from misconfigurations that stop the Search Head Cluster members from restarting correctly?
Scenario: we use the Deployer to deploy a version of indexes.conf that c...
Hi everyone,
I want to deploy standard inputs for ca. 50 linux UFs via custom apps. Since there is a difference between standard log paths on Debian and RedHat flavored systems I want to know if t...
Hello Everyone,
I am trying to identify the system failure based on the below sample data :-
ABCD AB1234 USERID SYSTEM
ABCD AB1234 XXXXX
ABCD AB1234 YYYYY
ABCD A...
Would like to ask on how can we determine if the System Health being shown is still within threshold and will not affect the Phantom performance.
How can we determine if we have good or bad t...
...o be a "from", so makes no sense to me for splunk to be there. I was expecting to see a bunch of systems and their log files as inputs, yet so far I cannot find any of (I just got admin and our s...
Hi, I have a Splunk Enterprise(8.1.0) account setup through my company. I am able to login to it online. But how do i set/install this Enterprise account onto my local system(W...
hi question regarding the wineventlog system collection.
for some reason splunk is only displaying event code 7036. i have a 2004 code that i am trying to log and set an alert but it is not p...