Activity Feed
- Got Karma for Re: How do I use authorise.conf centrally to manage user role access to indexes?. 07-03-2023 01:54 AM
- Posted Re: How do I use authorise.conf centrally to manage user role access to indexes? on Getting Data In. 07-03-2023 01:48 AM
- Karma Re: How do I use authorise.conf centrally to manage user role access to indexes? for isoutamo. 07-03-2023 01:47 AM
- Karma Announcing Our Splunk MVPs for jhupka_splunk. 06-29-2023 02:20 AM
- Posted Re: How to manage authorize.conf and authentication.conf in a SHC? on Splunk Enterprise. 06-28-2023 07:51 AM
- Karma Re: How to manage authorize.conf and authentication.conf in a SHC? for dural_yyz. 06-28-2023 07:50 AM
- Posted Re: How to manage authorize.conf and authentication.conf in a SHC? on Splunk Enterprise. 06-28-2023 07:49 AM
- Posted How do I use authorise.conf centrally to manage user role access to indexes? on Getting Data In. 06-28-2023 06:06 AM
- Posted Re: How to manage authorize.conf and authentication.conf in a SHC? on Splunk Enterprise. 06-28-2023 05:43 AM
- Karma Re: How to manage authorize.conf and authentication.conf in a SHC? for richgalloway. 06-28-2023 05:40 AM
- Karma Re: How to manage authorize.conf and authentication.conf in a SHC? for richgalloway. 06-28-2023 05:40 AM
- Posted Splunk - current roles within the Bank of England on Career Resources. 03-11-2022 01:40 AM
- Posted Re: Splunk CB Response - compatible with Splunk Enterprise 7.3.3 on All Apps and Add-ons. 02-03-2020 05:38 AM
- Posted Splunk CB Response - compatible with Splunk Enterprise 7.3.3 on All Apps and Add-ons. 01-03-2020 07:24 AM
- Tagged Splunk CB Response - compatible with Splunk Enterprise 7.3.3 on All Apps and Add-ons. 01-03-2020 07:24 AM
- Tagged Splunk CB Response - compatible with Splunk Enterprise 7.3.3 on All Apps and Add-ons. 01-03-2020 07:24 AM
- Posted Re: Splunk server uptime - missing Splunk server details on Getting Data In. 11-12-2019 06:06 AM
- Posted Splunk server uptime - missing Splunk server details on Getting Data In. 10-14-2019 12:28 AM
- Tagged Splunk server uptime - missing Splunk server details on Getting Data In. 10-14-2019 12:28 AM
- Tagged Splunk server uptime - missing Splunk server details on Getting Data In. 10-14-2019 12:28 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 |
07-03-2023
01:48 AM
1 Karma
glad I asked the question @isoutamo , always wondered what the options were. Have gone down the create an AD account and then go from there, add the capabilities and what index these users can see. It was also more around having people in different roles. Thanks for info
... View more
06-28-2023
07:51 AM
thanks @dural_yyz do you have an example of the actual configuration. Thanks what I am struggling with at the moment, knowing what the config should look like in authorise.conf cheers
... View more
06-28-2023
07:49 AM
hi @dural_yyz many thanks for the response. Do you have an example of what the config likes. I know what I am trying to achieve but struggling with what the actual config should look like
... View more
06-28-2023
06:06 AM
we have a 6 node SHC Want to use the deployer to push out authorise.conf so that we can manage the user/role/index access centrally. Looking for an example of how you control which index is seen by which user/role For example the role would look like [mail team] cumulativeRTSrchJobsQuota = 0 cumulativeSrchJobsQuota = 0 importRoles = user srchIndexesAllowed = mailgatewaylogs;maillogs;emailscanlogs srchMaxTime = 8640000 How do i specify users to have that have the mail team role ? user1:mail team user2:mail team user3:mail team
Not been able to find any reference or example as to how best to set this configuration centrally. Thanks in advance
... View more
06-28-2023
05:43 AM
Agree with @richgalloway the gui doesnt allow the flexibility to manage users / roles. Although it would be nice to see some clear documentation as to how to set this up from a deployer server correctly. Does anyone have any configuration examples ?
... View more
03-11-2022
01:40 AM
Just wanted to make you all aware that there are currently 2 roles available within the Bank of England Principle Engineer (Monitoring) - Closes 21/03/2022 https://www.linkedin.com/jobs/view/2940585146 Platform Engineering - Monitoring Engineer - Closes 15/03/2022 https://www.linkedin.com/jobs/view/2955787641 If you are interested, look at the links and follow the instructions if you want to apply. Position Title Principle Engineer (Monitoring) & Platform Engineering - Monitoring Engineer Location London UK Rate or Compensation See links above for full details W2/1099 (employee/contractor) Bank of England Any remote options or flexibility, or state that there is none The Bank of England does offer flexible working A complete description of the role, duties, responsibilities, etc. See links above for full details
... View more
02-03-2020
05:38 AM
hi, thanks for the information, looking at SplunkBase, there are the following apps for Carbon Black
https://splunkbase.splunk.com/apps/#/search/carbon%20black/
What one is the CB Response Eventforwarder app ?
Cheers
Paul
... View more
01-03-2020
07:24 AM
hi,
Looking to upgrade Splunk Enterprise from 7.2.4 to 7.3.3 and wanted to know is the CB Response app (ver 2.1.4) is compatible with Enterprise 7.3.3
Looking on Splunkbase it only does'nt mention version 7.3 at all.
https://splunkbase.splunk.com/app/3336/
Does anyone know if CB Response version 2.1.4 does work on Splunk Enterprise 7.3.3 without any issues ?
Thanks
Paul
... View more
11-12-2019
06:06 AM
cheers for the info richgalloway
... View more
10-14-2019
12:28 AM
Hi all,
I am running the below query, I get responses from some of my Splunk servers but not all ?
| rest /services/server/info | eval LastStartupTime=strftime(startup_time, "%Y/%m/%d %H:%M:%S")
| eval timenow=now()
| eval daysup = round((timenow - startup_time) / 86400,0)
| eval Uptime = tostring(daysup) + " Days"
| table splunk_server LastStartupTime Uptime
Is there anything I am missing on the servers that are not reporting back ?
Cheers
Paul
... View more
07-03-2019
05:11 AM
hi all,
I have had a number of scheduled searches that failed, all returning the same errors.
WARN : Eventtype 'xxxxxxxx' does not exist or is disabled.
WARN : [INDEXER 1] Eventtype 'xxxxxxxx' does not exist or is disabled.
WARN : [INDEXER 2] Eventtype 'xxxxxxxx' does not exist or is disabled.
WARN : [INDEXER 3] Eventtype 'xxxxxxxx' does not exist or is disabled.
WARN : [INDEXER 4] Eventtype 'xxxxxxxx' does not exist or is disabled.
Could someone explain why the indexers were returning the errors when all eventtypes are located on the search heads ?
cheers
Paul
... View more
- Tags:
- splunk-enterprise
06-12-2019
05:07 AM
hi all,
I have seperate drive for my hot/warm and cold data.
The hot/warm drive is near capacity.
Looking to find an easy way to calculate how much data each index will hold.
One example index config set is as below
10955Mb ingest per day (10.9Gb)
MazDataSize = 750mb (max size in MB for a hot bucket to reach before it rolls to warm)
maxWarmDBCount = 436 (max number of warm buckets)
maxtotalDataSize = 4328249mb (4328Gb) (maximum size of the index (in Mb)
frozenTimePeriodinSecs = 34128000 (395days in seconds)(number of seconds after which indexed data rolls to frozen)
overall retention = 395 (13months)
overall warm in days = 30
I would like to know how i can work out what size this indexed data should take up on my hot/warm and cold drives.
The split of the 4328Gb between the hot/warm & cold drives over 13months.
Does anyone know how best to calculate this ?
Cheers
Paul
... View more
05-13-2019
07:14 AM
hi Gurlest, No update has been provided by Splunk or any of the users from Splunk answers.
... View more
04-23-2019
07:46 AM
hi, Does anyone have stencils that are compatible with Visio 2010 ? I need files that have a VSS file extenstion, I cant import .VSSX files into Visio 2010
... View more
12-13-2018
05:48 AM
Hi,
I have been unable to locate any future updates on this topic ?
We are running 7.2.1 and I would like to know if there is still no way to fix a corrupt archived journal.gz file
Cheers
Paul
... View more
12-12-2018
01:21 AM
hi,
The link provided below by gdavismn does not return anything,
https://answers.splunk.com/answers/550473/replication-was-unsuccessful-failed-because-remote.htm
the link is missing the last l on html
add the l and the link works. See full link below
https://answers.splunk.com/answers/550473/replication-was-unsuccessful-failed-because-remote.html
... View more