Activity Feed
- Posted How to configure indexes.conf for bucket retention and rotation policy? on Deployment Architecture. 08-18-2014 11:04 AM
- Tagged How to configure indexes.conf for bucket retention and rotation policy? on Deployment Architecture. 08-18-2014 11:04 AM
- Tagged How to configure indexes.conf for bucket retention and rotation policy? on Deployment Architecture. 08-18-2014 11:04 AM
- Tagged How to configure indexes.conf for bucket retention and rotation policy? on Deployment Architecture. 08-18-2014 11:04 AM
- Tagged How to configure indexes.conf for bucket retention and rotation policy? on Deployment Architecture. 08-18-2014 11:04 AM
- Posted Free up space on the index on Knowledge Management. 06-13-2014 01:34 PM
- Tagged Free up space on the index on Knowledge Management. 06-13-2014 01:34 PM
- Tagged Free up space on the index on Knowledge Management. 06-13-2014 01:34 PM
- Tagged Free up space on the index on Knowledge Management. 06-13-2014 01:34 PM
- Posted Limit the number of files indexed on Getting Data In. 03-28-2014 10:48 AM
- Tagged Limit the number of files indexed on Getting Data In. 03-28-2014 10:48 AM
- Tagged Limit the number of files indexed on Getting Data In. 03-28-2014 10:48 AM
- Posted Re: mapping users to role on Security. 03-27-2014 09:07 AM
- Posted mapping users to role on Security. 03-27-2014 07:38 AM
- Tagged mapping users to role on Security. 03-27-2014 07:38 AM
- Tagged mapping users to role on Security. 03-27-2014 07:38 AM
- Tagged mapping users to role on Security. 03-27-2014 07:38 AM
- Tagged mapping users to role on Security. 03-27-2014 07:38 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 | |||
0 | |||
0 | |||
0 |
08-18-2014
11:04 AM
I have an index called "sharp" where currently I have ~ 90 days worth of data in the hotbucket (db directory).
For 90 days worth of data it takes up about 130 gigs of space.
I want to bucket retention and rotation in such a way-
upto 90 days worth of index files = stays in hot bucket ( we should be able to search up to 90 days' data)
more than 90 days worth of index files = can be moved to frozen (can be deleted immediately)
What are the settings I should use in the indexes.conf file?
... View more
06-13-2014
01:34 PM
I have quite a few hot db and warm in one of my index - sharp. Can I delete the files under the rawdata directory like the journal.gz to clean up some space?
Will that impact the index in any way?
... View more
03-28-2014
10:48 AM
I have the following entry in my $SPLUNK_HOME/etc/system/local/inputs.conf file --
[monitor:///appl/sharp/logs/*.fip]
host = trpramprptapp1.vm.itg.corp.us.shldcorp.com
sourcetype = sharp_fip
index = sharp
ignoreOlderThan = 1d
the dahsboard that we have is still reindexing all the log files, even thoough we have specified to not index the data older than 1 day.
... View more
- Tags:
- input
- inputs.conf
03-27-2014
09:07 AM
The only problem is that I cannot add all users like that. Is there any way to set all users to have "user" role by default.Something like --
user = ALL
or
user = *
I tried both but not working.
... View more
03-27-2014
07:38 AM
Hi,
I have created LDAP configuration in our SPLUNK deployment.
Version 6.0
DO NOT EDIT THIS FILE!
Please make all changes to files in $SPLUNK_HOME/etc/system/local.
To make changes, copy the section/stanza you want to change from $SPLUNK_HOME/etc/system/default
into ../local and edit there.
This file configures authentication.
[authentication]
authType = LDAP
authSettings = SHC
Note: the caching specified in this stanza only applies to scripted authentication.
If you are using scripted authentication, you can override these cache timing values in
your $SPLUNK_HOME/etc/system/local/authentication.conf
[SHC]
host = XXXXXXXXXXXXXXXXXXXXX
port = 389
SSLEnabled = 0
bindDN = anonymous
User Configurations
realNameAttribute = cn
userBaseDN = ou=people,o=intra,dc=sears,dc=com
userBaseFilter = (objectclass=*)
userNameAttribute = uid
Group Configurations
groupBaseDN = ou=people,o=intra,dc=sears,dc=com
groupBaseFilter = (objectclass=*)
groupMappingAttribute = uid
groupMemberAttribute = uid
groupNameAttribute = uid
[roleMap_SHC]
admin = lbirnba;pbussie;rsen0;vjaiswa
All the users have got added. But they they are not able to login(except for the admin users). I think I need to assign each user to a role before they can login. I am thinking of assigning the "user" role to all users. How do I achieve that without using groups. We do not use groups in our LDAP.
... View more