InSplunk Enterprise you can set the default searchindex per user. InSplunkLight you cannot it seems?
I read another post which said you can edit the \etc\system\default\indexes.conf file and s...
Hi,
Can the existing Splunk App(s) be read out with a search? I would like to assign the service to an app via dropdown in a service request (other tool) - so in a first step I have to read o...
Hi all,
Like the title says, is it possible to run SplunkLight with 2 indexers and a search head? Or is this a Splunk enterprise only configuration?
Many thanks,
I am using Splunklight and have a <500 MB indexed file license limit. I am using 5 universal forwarders which are all in Windows and 2 local dirs on local Linux (Splunklight server local m...
All,
I had SplunkLightinstalled (version 6.4.0). Tried to log in, but noticed that the license had expired, so I switched to free. Great. Now I get:
This pool has exceeded its configured p...
Hi everyone !
I am a new user inSplunk (Great application and these days very useful); I read this document and I tried to reproduce the search but in my Splunk Free it does not work, reporting t...
There is a bug in the Job "Share" button: It only works for admins! Analysts have mentioned that within the search head, they are unable to share jobs with one other. This means that while a...
...ips, and Data Descriptor articles which help you see everything that’s possible with data sources and data types inSplunk.
Here’s a full breakdown of everything we’ve published in the past month....
we use splunklightin 7.1.0. I deleted a User last week and did not recocnized that their was a sheduled search of this user. On the attention message i was told today to view the orphaned searches...
I'm forwarding traffic from a window file server to a splunklightinstance. The index where the data is received is wineventlog. That index isn't searchable. How do I add that index to the d...