I got looking at the app and it was version 4.1.1. I look up the app on Splunk Apps and the current version is 4.3. Shutdown splunk, upgraded the app and turned splunk back on. Now i can sell all regions.
... View more
I go to add an AWS CloudWatch Logs input and I do not see Canada (Central) region. I have log inputs from US East and US West working fine. When I select the AWS Region drop down I'm missing Canada, UK, Mumbai and Ohio.
... View more
i didn't update the server.conf. After i did that and restarted the forwarder the indexer picked it up and all of the old data is searchable by "hostname" now. Thanks
... View more
I fixed the name of a host on the forwarder. It was showing as "hostname.domain.com" instead of just "hostname". I fixed the name and restarted the Splunk service.
Now i have 2 different host names showing in Splunk up for the same host. How could i show all of the "hostname.domain.com" data as "hostname" also?
... View more
I'm trying to setup Splunk DB Connect with a new DB input. When i get to the choose and preview table i'm doing an advanced input type, it keeps failing with error "Checkpoint value is required in Advanced input mode". Not sure what it is wanting for a checkpoint value.
... View more
The device does feed data into the splunk add-on but i want to filter the data before it gets there. I've been able to do it with (example) specific windows event logs but i want to do the same with the cisco asa logs.
... View more
Professional Services set up our Splunk and has it set up to where it pulls in the Cisco ASA data. The device feeds data into the Splunk Add-on for Cisco ASA but I would like to filter the data before it gets there since I don't need all of the logs coming from the device. How would I go about filtering these logs to not be indexed?
... View more