Activity Feed
- Got Karma for Re: What is the difference between RollOverSummary and Usage types of in license_usage.log?. 03-09-2022 07:06 AM
- Got Karma for Re: Get user's search history. 11-26-2020 08:27 AM
- Karma Custom date format extraction using datetime.xml for dshakespeare_sp. 06-05-2020 12:49 AM
- Karma Re: Custom date format extraction using datetime.xml for dshakespeare_sp. 06-05-2020 12:49 AM
- Karma Re: Are any Fluentd apps Splunk vetted/supported? Or is there a preferred cloud-native solution for logging Kubernetes logs? for sduff_splunk. 06-05-2020 12:49 AM
- Karma why the indexers are initiating rolling-restart automatically? for AbilashSe. 06-05-2020 12:49 AM
- Karma Re: Is anyone interested in closing the security holes that Splunk leaves open with mongod ? for jeremiahc4. 06-05-2020 12:48 AM
- Karma Is there any way to get Splunk to replicate search history in a search head cluster? for peter_holmes_an. 06-05-2020 12:48 AM
- Karma Re: Is there any way to get Splunk to replicate Search History in a Search Head Cluster? for somesoni2. 06-05-2020 12:48 AM
- Karma Re: Is there any way to get Splunk to replicate Search History in a Search Head Cluster? for jplumsdaine22. 06-05-2020 12:48 AM
- Karma Re: Why do I get this error when configuring the universal forwarder: SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed? for dwaddle. 06-05-2020 12:48 AM
- Karma Re: Universal Forwarder 6.5 on Windows Server 2008 32-bit? for martin_mueller. 06-05-2020 12:48 AM
- Karma Re: For Splunk Enterprise, Splunk Light, and Hunk pre 6.3, default root certificates expire on July 21, 2016 - Recommendations? for Ellen. 06-05-2020 12:48 AM
- Karma Why is an indexer in a cluster reporting "CMMessages - got genid thats invalid or out of range, setting to INVALID_GENID"? for gpaks. 06-05-2020 12:48 AM
- Karma Re: Why is an indexer in a cluster reporting "CMMessages - got genid thats invalid or out of range, setting to INVALID_GENID"? for dshakespeare_sp. 06-05-2020 12:48 AM
- Karma Re: Universal forwarder consuming 100% CPU. "WARN TimeoutHeap - Either time adjusted forwards by, or event loop was descheduled for 490844ms" for regriffith. 06-05-2020 12:48 AM
- Karma Why am I getting incorrect results from btool during diagnostics for a Splunk 6.3.1 Windows universal forwarder? for wyfwa4. 06-05-2020 12:48 AM
- Karma Page Redering issues for Incident Review in Enterprise Security after upgrade to 6.5 for att35. 06-05-2020 12:48 AM
- Karma Re: Page Redering issues for Incident Review in Enterprise Security after upgrade to 6.5 for smoir_splunk. 06-05-2020 12:48 AM
- Karma Re: Why are alerts not working after upgrade to Splunk 6.5.0? for christopherr_sp. 06-05-2020 12:48 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
1 | |||
1 | |||
0 | |||
0 | |||
0 |
10-07-2019
08:08 AM
I believe you are right as per; https://answers.splunk.com/answers/636862/error-usermanagerpro-usersystem-had-no-roles.html
... View more
09-11-2019
04:06 AM
I downvoted this post because this answer was but is no longer valid.
... View more
09-11-2019
04:06 AM
The Latest Support Stance (As of September 2019) is:
Fix: Splunk will NOT commit to version predictability on MaxMind DBs (MMDBs). MMDBs can and most likely will change in line with version upgrades as per the Cloud Maintenance Policy:
https://www.splunk.com/en_us/legal/splunk-cloud-service-maintenance-policy.html
Workaround: If a customer requires version predictability, they may package the MMDB in a custom app. This app WILL be required to undergo vetting . If you wish to discuss or request this, please file a Support ticket.
... View more
03-04-2019
07:08 AM
I downvoted this post because searchhead--->settings--->all configurations--->reassign knowledge objects are not real/valid options.
... View more
12-19-2018
02:46 AM
I downvoted this post because this answer is obsolete (and now wrong). see splunk internal engineering reference; spl-154283
... View more
04-30-2018
01:39 AM
The official Splunk support stance as of 2018-04-30 is that Docker is NOT supported.
If you would like to see official support of docker in the future, please talk to your account team and upvote the following enhancement request; PBL-11109
... View more
03-26-2018
01:04 AM
https://answers.splunk.com/answers/111566/show-source-not-available.html
Solution: Making sure the search is well finalized before getting to source of an result/event.
... View more
08-21-2017
04:05 AM
Reading this might help:
https://docs.splunk.com/Documentation/Splunk/6.5.2/Indexer/Anomalousbuckets
This query might also be useful:
| rest /services/cluster/master/info
| fields buckets_to_fix.*.latest.reason
| transpose
| rename column AS bucket "row 1" AS reason
| rex field=bucket "buckets_to_fix\.(?.*?)\.latest\.reason"
| rex field=bucket "(?[^~]*?)~"
| rex mode=sed field=reason "s/[0-9A-Z]{8}-[0-9A-Z]{4}-[0-9A-Z]{4}-[0-9A-Z]{4}-[0-9A-Z]{12}/{PEER}/"
... View more
06-23-2017
01:06 AM
1 Karma
Your first query references; "source=license_usage.log"
Your second uses; "source=*license_usage.log"
Was this intentional? Did you mean to search;
1=license_usage.log only
2=license_usage.log, license_usage.log.1 and license_usage.log.2, etc
3=Something else.
... View more
06-20-2017
04:09 AM
If you think btool is broken I recommend you log a support case and get this look at.
The most common reason for this to happen is that you have an inconsistent configuration which btool can't properly interpret.
We see this commonly where users are switching between Windows and Linux systems.
I recommend reviewing your .conf files for the presence of characters like ^M (carriage return).
More info on this here:
https://docs.splunk.com/Documentation/Splunk/6.6.1/Admin/DifferencesbetweenunixandwindowsinSplunkoperations
... View more
05-11-2017
02:42 AM
Apparently this message is meaningless by itself.
The error is probably a socket error.
Normally a line before that one reveals the true error.
... View more
05-09-2017
07:12 AM
3 Karma
This appears to be an issue with the global export permissions on the splunk_app_for_unix taking precedence over the default navigation options of the barebones template used in your custom app:
Splunk internal engineering reference = TAG-12427
Workaround:
Settings/User Interface/Views
Fix the Unix app permission from "Global" to "App only".
Settings/User Interface/Navigation Menus
Fix the Unix app permission from "Global" to "App only".
Bump the server.
... View more
05-09-2017
12:14 AM
Sounds like there is something going wrong with the KV store (mongo) during this operation.
First place I would look is in mongod.log. ($splunk_home/var/log/splunk/mongod.log)
Second thing I would do is make sure your KVstore is loading ok normally. I would start by checking stuff like certs which KV store uses to self-validate:
https://answers.splunk.com/answers/404979/trying-to-run-the-distributed-management-console-g.html
Third thing I would do is confirm you actually use KVstore here, and that this message is not a red herring.
... View more
05-04-2017
06:25 AM
Warning of the form "WARN CMRepJob - _rc=0 statusCode=500 err=No error" in splunkd.log.
Found on the cluster master of an index cluster.
Cluster master appears busy replicating buckets following a change to maxdataSize stanza's, so may be related to this.
... View more
- Tags:
- clustering
- index
04-12-2017
05:29 AM
Common Answers seem to be:
https://answers.splunk.com/answers/337702/splunk-db-connect-2-why-am-i-getting-error-cannot.html
⎝ Increase max connections.
https://answers.splunk.com/answers/488736/why-does-splunk-dbconnect-execute-query-transactio.html
⎝ useConnectionPool = false
https://answers.splunk.com/answers/475392/splunk-db-connect-how-to-resolve-dbxquery-error-fa.html
⎝ upgrade to 2.4.0
⎝ maxWaitMillis = 60000
... View more
03-06-2017
09:01 AM
Downloads are too big to attach directly. Available here instead:
https://splunk.box.com/s/7xts7re5sok6vvazb4yhdn93pekornbi
... View more
03-06-2017
07:46 AM
1 Karma
A Hack, which would be totally unsupported would be:
0=Download and extract the attached zip.
1=Create a copy of existing splunkjsstack_1.4/static/splunkjs/config.js as backup and keep it somewhere outside of your project directory. This is just to restore the original config.js file if something goes wrong with the new test file.
2=Now, replace the above file with the attached config.js file
3=Test in your .html doc (sample doc attached).
... View more
03-06-2017
07:34 AM
1 Karma
This (using the print/export buttons via SplunkJS) is not currently supported.
Enhancement request to add support for this is: DVPL-7148
... View more
03-06-2017
07:32 AM
I'm trying to add print/export icons using Splunk's splunkjs framework and splunkjs/mvc/searchcontrolsview, to display the job menu and buttons
Docs I'm following:
http://docs.splunk.com/DocumentationStatic/WebFramework/1.3/compref_searchcontrols.html
Observations:
Use of the ResultLinkView (splunkjs/mvc/resultslinkview) dependency even without actually using it results in JS error: "Uncaught Error: getConfigValue - MRSPARKLE_PORT_NUMBER not set, no default provided"
... View more
02-01-2017
10:31 AM
Not enough info really.
It could be a few things, for example;
As per: https://answers.splunk.com/answers/67327/splunk-java-sdk-connection-to-splunk-failed.html
And: https://answers.splunk.com/answers/206990/why-am-i-getting-a-splunk-java-sdk-handshake-failu.html
"Ensure that your connection credentials are correct, notably that you are using HTTPS over Port 8089 to your SplunkD Server.
As a guess, you might be trying to connect to SplunkWeb on port 8000, which is not where the REST endpoints are located."
As per: https://answers.splunk.com/answers/209379/no-appropriate-protocol-protocol-is-disabled-or-ci.html
"Splunk needs to release a new jar without SSLv3 hardwired (in HttpService.java) in order to make this work with the latest Java 8. Meanwhile you need to stick with Java 7 or build your own jar from the SDK package and use SSLv2 instead."
... View more
02-01-2017
10:12 AM
1 Karma
| rest /servicesNS/-/-/saved/searches splunk_server=local
As per: https://answers.splunk.com/answers/231694/how-can-i-get-a-list-of-all-saved-searches-from-al.html
Also: https://answers.splunk.com/answers/12488/how-to-list-saved-searches.html
... View more
02-01-2017
08:28 AM
1 Karma
Make sure your custom logo is in .png format.
Sample Setup might look like this:
Via GUI:
Settings/Server Settings/Email Settings/PDF Report Settings
Via CLI:
./etc/system/local/alert_actions.conf
[email]
mailserver = mymailserver
pdf.header_left = logo
pdf.header_right = none
pdf.logo_path = search:/image001
pdf.html_image_rendering = 0
Put the custom image here: /opt/splunk/etc/apps/search/appserver/static/image001.png
Test via Ad-Hoc Search:
"index=main | head 5 | sendemail to= server= subject="Here is an email notification" message="This is an example message" sendresults=true inline=true format=raw sendpdf=true"
As per: http://docs.splunk.com/Documentation/Splunk/latest/Alert/Emailnotification
Errors log to: /opt/splunk/var/log/splunk/pdfgen.log
Further Reading:
http://docs.splunk.com/Documentation/Splunk/latest/Admin/Alertactionsconf
http://docs.splunk.com/Documentation/Splunk/latest/Alert/Emailnotification
https://answers.splunk.com/answers/495250/pdf-generation-with-custom-logo-failing.html?minQuestionBodyLength=80
... View more
02-01-2017
08:17 AM
2 Karma
Cause:
This appears to be a defect with the PDF generator's handling of folders.
Splunk bug reference = SPL-136094
Workaround:
When I put images here;
/opt/splunk6.5.0/etc/apps/search/appserver/static/
Result = Working fine with my image.
When I put images here;
/opt/splunk6.5.0/etc/apps/search/appserver/static/myfolder
Result = PDF generation breaks with error of the form;
"pdfrenderer:427 - Failed to retrieve customize logo error [Errno 2] No such file or directory:"
... View more
02-01-2017
08:14 AM
I have set a custom image/logo for my generated alerts.
My Setup:
OS=CentOS07
Splunk=6.5.0
Architecture=Standalone instance (SH and IDXer in one box)
$SPLUNK_HOME=/opt/splunk6.5.0
My Config
./etc/system/local/alert_actions.conf
[email]
mailserver = mymailserver
pdf.header_left = logo
pdf.header_right = none
pdf.logo_path = search:myfolder/image001
pdf.html_image_rendering = 0
I have put my custom image here:
/opt/splunk6.5.0/etc/apps/search/appserver/static/myfolder/image001.png
PDF generation is broken with error of this form in $SPLUNK_HOME/var/log/splunk/pdfgen.log;
"pdfrenderer:427 - Failed to retrieve customize logo error [Errno 2] No such file or directory:"
... View more
02-01-2017
07:14 AM
3 Karma
As per: http://docs.splunk.com/Documentation/Splunk/latest/Alert/Emailnotification
You can send email notifications directly from the sendemail search command. Here is an example:
index=main | head 5 | sendemail to= server= subject="Here is an email notification" message="This is an example message" sendresults=true inline=true format=raw sendpdf=true
... View more