Activity Feed
- Got Karma for Re: How can I control the client's Host Name that appears in Forwarder Management?. 10-26-2021 09:37 AM
- Got Karma for Re: How can I control the client's Host Name that appears in Forwarder Management?. 10-26-2021 09:36 AM
- Karma Mimecast for Splunk not showing Target Threat Protection Data for summitsplunk. 06-05-2020 12:49 AM
- Karma Anyone have an SCCM app that works with Splunk 7.x? for heatonjl. 06-05-2020 12:49 AM
- Karma MSO365 Reporting add on for Splunk intermittently stops sending data for jakewhittet. 06-05-2020 12:49 AM
- Karma Website Monitoring Application - Inputs do not replicate on search head cluster for gjanders. 06-05-2020 12:49 AM
- Karma Re: Restart a splunk app via script for Damien_Dallimor. 06-05-2020 12:48 AM
- Karma Re: Is anyone using CI/CD to deploy Splunk apps? for vliggio. 06-05-2020 12:48 AM
- Karma Re: Is anyone using CI/CD to deploy Splunk apps? for vliggio. 06-05-2020 12:48 AM
- Karma Re: Button to pause then resume email alerting for proylea. 06-05-2020 12:48 AM
- Karma PowerShell sample for HTTP Event Collector for gmartins_splunk. 06-05-2020 12:48 AM
- Karma Re: PowerShell sample for HTTP Event Collector for halr9000. 06-05-2020 12:48 AM
- Karma Re: What is a simple way to clear some space if I'm running out of disk space allocated for indexes? for somesoni2. 06-05-2020 12:48 AM
- Karma Re: How to embed a Twitter widget in a Splunk dashboard? for msivill_splunk. 06-05-2020 12:48 AM
- Karma Re: anyone successfully run clean-dispatch in 6.2.X search head cluster? for masonmorales. 06-05-2020 12:48 AM
- Karma Splunk Stream: Is it possible to pull SSH fingerprint? for jeff. 06-05-2020 12:48 AM
- Karma Re: Issues executing TSTATS search for Damien_Dallimor. 06-05-2020 12:48 AM
- Karma Re: Why am I still seeing data older than my frozenTimePeriodInSecs retention setting? for ryanoconnor. 06-05-2020 12:48 AM
- Karma Re: Why does my Splunk forwarder transmit incomplete events for my rsyslog server? for jtacy. 06-05-2020 12:48 AM
- Karma FEATURE REQUEST: Splunk Alert: All Clear Notification for bandit. 06-05-2020 12:48 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 | |||
0 | |||
0 | |||
0 | |||
0 |
04-01-2020
11:08 AM
Looking for a way to ingest all outgoing mail from the mailbox as well. Just was wondering if anyone has had any luck with something like that?
... View more
- Tags:
- IMAP Mailbox
06-07-2017
07:15 AM
You may need to run a diag and open a case with Splunk as more details/error information would be helpful. I have had issues with a particular app and needed to edit the web.conf but your information is a little unclear - have a look at the following, it may help.
https://answers.splunk.com/answers/329466/why-am-i-getting-an-unresponsive-setup-screen-tryi.html#answer-342185
... View more
05-22-2017
08:26 AM
I'm having difficulties converting Microsoft's LastBootUpTime into Epoch taking the timezone offset into account to get an Epoch in GMT value for comparison. Would anyone have any ideas to assist?
LastBootUpTime="20170522110049.412726-240"
Thanks,
Paul
... View more
04-04-2017
03:29 AM
After making changes and letting them persist for awhile I restarted the DMC - this did not change the instance name to the configured new instance name even after a restart of the DMC. I then applied all changes - and that did the trick!
Apply Changes on DMC -> Settings -> General Setup
... View more
04-04-2017
03:24 AM
I downvoted this post because there needs to be a better way to accomplish this. for a small/new environment this is fine but when you have 50+ devices this isn't a viable solution.
... View more
03-31-2017
06:27 AM
https://deploymentserver:8089/services/deployment/server/clients?count=0
Just to close this out and help anyone else find this answer more quickly.
... View more
03-31-2017
06:26 AM
https://deploymentserver:8089/services/deployment/server/clients?count=0
Just to close this out and help anyone else find this answer more quickly.
... View more
03-30-2017
12:50 PM
version/OS info would help, have you tried restarting from the CLI?
... View more
03-30-2017
12:45 PM
I'd love to see the powershell script you have or a partial as i"ll be needing to do the same.
... View more
03-30-2017
12:42 PM
Looks like 6.2.8 is the latest from what I see:
https://www.splunk.com/page/previous_releases/universalforwarder#x86_64windows
Windows 7, 8 and 8.1 (64-bit)
Windows Server 2003, 2003 R2, 2008, 2008 R2, 2012 and 2012 R2 (64-bit) 6.2.8:
splunkforwarder-6.2.8-275559-x64-release.msi
Release Notes
... View more
03-29-2017
02:18 PM
1 Karma
https://host:8089/services/deployment/server/clients?count=0 to pull the full Universal Forwarder list.
https://docs.splunk.com/Documentation/Splunk/6.5.2/RESTREF/RESTdeploy
deployment/server/clients/{name}
https://:/services/deployment/server/clients/{name}
Get client information or remove a client.
DELETE
Remove the specified client from the deployment server registry. The next time the client "phones home" the record is re-created.
... View more
02-22-2017
01:52 PM
Can't wait, looking forward to it!
... View more
02-08-2017
11:00 AM
Something that's bitten me in the past, are you testing from the CLI as the same user that Splunk is running as?
... View more
01-12-2017
12:10 PM
Great news, I've been on the lookout for this since I saw the recording! Thanks
... View more
11-30-2016
05:23 AM
I don't believe that you will be able to fix this with the Splunk tuning, have you looked at what the other remote application is doing and how the requests are being opened? More information on the remote application would be helpful. Here's a link that might be helpful.
http://unix.stackexchange.com/questions/10106/orphaned-connections-in-close-wait-state
... View more
11-18-2016
06:39 PM
1 Karma
My apologies, I should have posted this. This works up to 6.4.3 UF's... I would still prefer to have the ability to overwrite the hostname as I needed to rewrite some validation scripts to account for this using the clientName field:
Windows
C:\Program Files\SplunkUniversalForwarder\splunkforwarder\etc\system\local\deploymentclient.conf" and change the "clientName = XXX" This requires creating a "deployment-client" stanza and adding a "clientName = XXX" before the target-broker and targetURI:
Example:
[deployment-client]
clientName = XXX
[target-broker:deploymentServer]
targetUri = 10.1.1.1:8089
... View more
10-20-2016
08:53 AM
Glad to see I'm not suffering alone! I'm looking to leverage the Deployment Server an/or DMC to come up with a workable solution. With the amount of cloning and remames this is a bit of an issue with nearly 7000 UF's.
... View more
10-19-2016
07:31 AM
I am looking for ideas on how to verify hostnames are correct when writing to the indexes and when phoning home as I have encountered a fair number of UF's that were renamed and this is causing some reporting issues. I was looking for ideas on how other may have handled this, particularly in a mixed environment of Windows and Linux.
... View more
10-13-2016
06:20 AM
Did anyone get this regex to work?
... View more
07-14-2016
07:07 PM
1 Karma
Thanks for your response, however the documentation doesn't align with the reality of my experience and testing.
... View more
07-14-2016
03:24 PM
Did you try the new app? https://splunkbase.splunk.com/app/2648/
... View more
07-14-2016
02:30 PM
I am looking to override the Host Name in the Forwarder Management but I have been unsuccessful. Changing the clientName in deployment.conf changes the Client Name but not the Host Name.
We have changed the inputs.conf to reflect the new name but need to have consistency for scripting with the Host Name in Forwarder Management.
All changes/testing were done in C:\Program Files\SplunkUniversalForwarder\etc\system\local and we need to be able to do this in both Windows and Linux - any idea what I may be missing?
... View more
05-23-2016
07:34 AM
As rc.local runs these commands after Splunk starts I put this in init.d so upon restart Splunk logs the correct/current status on reboot.
... View more
05-18-2016
11:05 AM
Wow, this seems fairly counter-intuitive since the Save button is grayed out until you run the search.
... View more
03-07-2016
01:53 PM
I'm not sure if I understand the difference? If you are changing the label you need to change it on all of the search heads in the SHC in addition to having it consistent on the Deployer. A word of caution on 6.3.2, please ensure you have the config correct for the ./splunk init shcluster-config command - I had to re-configure the entire cluster to get this functioning properly. Additionally you will want to try to avoid using a "$" in the secret as when I got around to installing apps this appeared to cause issues in the CLI.
... View more