Activity Feed
- Posted Re: Deployment Server Total Downloads in the Last Hour on Deployment Architecture. 06-16-2023 09:25 AM
- Posted Re: Can the Splunk Add-on for Juniper extract SRX logs? on Getting Data In. 11-01-2021 08:06 AM
- Got Karma for estreamer.pipeline ERROR error: unpack requires a string argument of length 4. 07-23-2020 05:19 PM
- Got Karma for Re: Invalid key in stanza [Splunk_TA_f5_bigip_main]. 06-05-2020 12:48 AM
- Posted Re: Cisco eStreamer for Splunk : Narly all the events are getting timestamped to midnight? on All Apps and Add-ons. 02-06-2020 11:49 AM
- Posted Cisco eStreamer for Splunk : Narly all the events are getting timestamped to midnight? on All Apps and Add-ons. 01-30-2020 11:17 AM
- Tagged Cisco eStreamer for Splunk : Narly all the events are getting timestamped to midnight? on All Apps and Add-ons. 01-30-2020 11:17 AM
- Tagged Cisco eStreamer for Splunk : Narly all the events are getting timestamped to midnight? on All Apps and Add-ons. 01-30-2020 11:17 AM
- Posted estreamer.pipeline ERROR error: unpack requires a string argument of length 4 on All Apps and Add-ons. 01-28-2020 12:46 PM
- Tagged estreamer.pipeline ERROR error: unpack requires a string argument of length 4 on All Apps and Add-ons. 01-28-2020 12:46 PM
- Tagged estreamer.pipeline ERROR error: unpack requires a string argument of length 4 on All Apps and Add-ons. 01-28-2020 12:46 PM
- Posted Re: Anyone getting this error? DateParserVerbose - Failed to parse timestamp in first MAX_TIMESTAMP_LOOKAHEAD (128) on All Apps and Add-ons. 01-28-2020 12:12 PM
- Posted Re: Is there a systemd unit file for Splunk? on Splunk Search. 10-16-2019 03:18 PM
- Posted Re: Is there a systemd unit file for Splunk? on Splunk Search. 10-16-2019 02:35 PM
- Posted Re: TA Meraki: how do I fix the bug I found in my splunkd.log? on All Apps and Add-ons. 08-20-2019 01:46 PM
- Posted Re: "Error reading compressed journal while streaming: gzip data truncated". Are my Hadoop archived buckets corrupted, and how do I fix it? on Deployment Architecture. 12-26-2018 11:33 AM
- Posted Re: Could not read event. Results may be incomplete on Splunk Search. 11-26-2018 07:00 AM
- Posted Re: Can one use this app to send data to Elastic Stack on All Apps and Add-ons. 11-02-2018 01:04 PM
- Posted Re: Can one use this app to send data to Elastic Stack on All Apps and Add-ons. 11-02-2018 01:03 PM
- Posted Can one use this app to send data to Elastic Stack on All Apps and Add-ons. 11-02-2018 08:46 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 | |||
1 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 |
06-16-2023
09:25 AM
I've been ignoring this number for 8 or 9 years now as it's never made any sense and doesn't correspond to the results of the queries mentioned above. How does this counter even work?
... View more
11-01-2021
08:06 AM
I'd like some clarification on this as well. Does the TA select the correct source type for these events?
... View more
02-06-2020
11:49 AM
Over that past week, we've seen the TA correctly ID the timestamps of events for most of a day and then another day it will chuck all the events is to a bin for midnight that day. Today we're seeing that it's choosing timestamps for 2017 and 2019!?
The following line in the default props.conf makes it seem like it's expecting a timestamp formatted like so dd/mm/yy hh:mm:ss
but, the data from our FMC contains only unix epoch time stamps.
[cisco:estreamer:log]
EXTRACT-encore_log_fields = ^(?P< timestamp > \d+-\d+-\d+\s+\d+:\d+:\d+,\d+)\s+
How do we fix that?
... View more
01-30-2020
11:17 AM
Heavy Forwarder is RHEL 7.7
Splunk binaries are 7.2.9.1
TA is version 3.5.8 (3.6.8) does the same.
We're getting the data and when one looks at the events they have proper unix timestamps in them but, when they are indexed they all get a time of midnight.
We tried this a few days ago on old VM (RHEL 6 & Splunk 6.6.12.1 ) that just couldn't keep up with the volume but, it did seem to timestamp properly....
Moving it to the new VM is when we found the timestamp issue.
How could I correct the timestamps in splunk?
... View more
01-28-2020
12:46 PM
1 Karma
I'm seeing a lot of these errors in the estreamer.log file.
This is with version 3.5.8
... View more
01-28-2020
12:12 PM
IS there a fix for this? I'm running 3.5.8 and seeing a lot of these warnings
... View more
10-16-2019
03:18 PM
Um, no. According to the document below 6.5 is not EOL yet.
https://www.splunk.com/en_us/legal/splunk-software-support-policy.html
We pay quite a bit of money for support, so why do we have to chase down things like this for a supported version of Splunk?
... View more
10-16-2019
02:35 PM
Is there an officially supported way to do this for Splunk 6.5.x that doesn't involve cutting and pasting from 10 different postings?
... View more
08-20-2019
01:46 PM
A co-worker of mine just discovered that we're seeing the same error in version 1.0.6.
Just wondering if that is fixed in later versions?
... View more
12-26-2018
11:33 AM
Has there been any progress?
... View more
11-26-2018
07:00 AM
I'm seeing a similar error. How would one ID the bucket that is a problem? What component should I put into Debug ?
... View more
11-02-2018
01:04 PM
Also your link is busted : (
... View more
11-02-2018
01:03 PM
The Splunk Add-on for Linux
... View more
11-02-2018
08:46 AM
Can it be configured to send data to Elastic and or Splunk ?
... View more
10-01-2018
10:31 AM
Can I do this with an envirnment variable?
I've had good luck defining SYSLOG_DIR in splunk-launch.conf and then referencing it in the path for a filemonitor.
This lets me have the name of the syslog node in the source and keeps my inputs.conf the same.
Can I do something similar to define an index in an inputs stanza?
... View more
08-23-2018
06:46 AM
There are some bugs in that feature. We've found that we have to restart our cluster master when the data re-balance just seems to get stuck : (
... View more
07-20-2018
07:09 AM
I forgot to mention that it's Splunk Enterprise 6.5.6
... View more
07-20-2018
07:08 AM
This isn't working as desired for us, ATM. One of my App guys is having problems were savedsearches.conf in /local is being merged/appended into savedsearches.conf in /default when we've used the excludeFromUpdate option for $app_root$/local. I've verified that this happens on the Search Head. The contents of the bundles are correct on both the deployment server and the search head.
... View more
07-20-2018
07:02 AM
We had the same problem. You can either delete the entry in the manifest file or give it the hash of the updated file.
... View more
07-06-2018
01:03 PM
This doesn't seem to work in 6.5.6.
Is there a way to just reload one serverclasss in 6.5.x ?
... View more
06-20-2018
02:39 PM
It seems to be back in Splunk 6.5.x if, one is running splunkd as a limited user. I just had this happen on an Indexer in Prod that was restarted via vmware.
I was able to recreate it in my QA environment. All one needs to do is mock up a pid file with ids from other processes that belong to another user like root.
... View more
04-24-2018
12:42 PM
My users also want drill downs on this. Is that possible?
... View more
04-19-2018
08:53 AM
It was an existing install. RHEL 6.x. It turns out the lun that the disk was on was accidentally filled up via a VMware snapshot.
... View more
04-18-2018
02:35 PM
They are not "myssql" logs. That's a typo that I can't seem to correct. It would Just be the logs for mssql instances.
... View more
04-18-2018
02:31 PM
My team is being asked to monitor logs for mssql instances and we're wondering how one does this when the drive letters to the logs change when sql cluster nodes change from active to passive?
... View more