Activity Feed
- Got Karma for Re: Universal forwarder 9.1.0 (linux) changed owner. 10-09-2024 02:37 PM
- Posted Re: Changing permissions for multiple eventtypes on Security. 08-22-2024 12:16 PM
- Got Karma for Re: Universal forwarder 9.1.0 (linux) changed owner. 06-24-2024 02:51 PM
- Got Karma for Re: Universal forwarder 9.1.0 (linux) changed owner. 06-04-2024 11:38 AM
- Got Karma for Re: Universal forwarder 9.1.0 (linux) changed owner. 04-04-2024 03:18 PM
- Got Karma for Re: Universal forwarder 9.1.0 (linux) changed owner. 02-21-2024 05:42 AM
- Got Karma for Re: Universal forwarder 9.1.0 (linux) changed owner. 02-21-2024 05:42 AM
- Got Karma for Re: Universal forwarder 9.1.0 (linux) changed owner. 02-09-2024 07:29 AM
- Got Karma for Re: Universal forwarder 9.1.0 (linux) changed owner. 11-09-2023 12:33 AM
- Posted Re: Universal forwarder 9.1.0 (linux) changed owner on Splunk Enterprise. 11-08-2023 02:55 PM
- Karma Re: Universal forwarder 9.1.0 (linux) changed owner for PickleRick. 11-08-2023 02:51 PM
- Karma Re: Universal forwarder 9.1.0 (linux) changed owner for auradk. 11-08-2023 02:51 PM
- Posted Re: Universal forwarder 9.1.0 (linux) changed owner on Splunk Enterprise. 11-08-2023 02:43 PM
- Karma Re: Universal forwarder 9.1.0 (linux) changed owner for auradk. 11-08-2023 02:43 PM
- Posted Re: My splunk agent service runs as NT SERVICE/SplunkForwarder user and I want to move it to a local account. on Getting Data In. 11-02-2023 02:59 PM
- Got Karma for Re: How to link Aruba Central (logs, reporting etcc) to Splunk server?. 09-29-2023 01:16 PM
- Got Karma for Re: Invalid Key in alert_actions.conf after upgrade to Splunk 9.0.0. 07-17-2023 09:44 AM
- Got Karma for Re: Invalid Key in alert_actions.conf after upgrade to Splunk 9.0.0. 06-26-2023 10:19 PM
- Posted Re: How to link Aruba Central (logs, reporting etcc) to Splunk server? on All Apps and Add-ons. 06-09-2023 01:01 PM
- Got Karma for Re: Invalid Key in alert_actions.conf after upgrade to Splunk 9.0.0. 05-19-2023 08:13 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 | |||
0 | |||
0 |
08-22-2024
12:16 PM
Hello! Checking in August 22, 2024 -- still not able to edit permissions on multiple objects at once.
... View more
11-08-2023
02:55 PM
4 Karma
This is a really cavalier response to such a major change. It is not a simple task to 'update automation' in large organizations, where you also need to consider multiple legacy systems. As was mentioned above, Splunk has never officially supported the installation of both Enterprise and Forwarder on the same server, so who does this change benefit?
... View more
11-08-2023
02:43 PM
4 Karma
I am so glad I found this thread. You are completely spot on on everything you said. It is infuriating for us as admins and embarrassing for Splunk as a brand that such major changes are implemented in minor version releases with little to no notice or documentation. Absolutely ridiculous to change default behavior of installer in a minor release. Period.
... View more
11-02-2023
02:59 PM
Do you have any docs/references for point 2? >> With older versions of UF, it was run with Local System user by default. New versions use a user with a bit more "trimmed" permissions.
... View more
06-09-2023
01:01 PM
1 Karma
yeah... just be aware that the token will show up in any tool that logs web traffic, since it is just plaintext in the url
... View more
04-26-2023
07:39 AM
1 Karma
this is not fixed in 9.0.4
... View more
04-26-2023
07:38 AM
3 Karma
Honestly. Nearly 1 year later and 2 version revisions and every fresh UF install done on every server throws this out-of-the-box warning. Not at all impressed
... View more
04-26-2022
11:37 AM
I've been trying to find an _internal or _audit trail log event showing when a Splunk Diag was created on a given server but have been unable to find anything in those indexes nor any documentation around it... Often for troubleshooting case tickets with Splunk support it becomes important to know when a diag was created on a server in the context of the timeline of the issue. The goal we have is to simply timechart critical events, including diag generation, by server/host so we can visualize what happened in what order. Anyone have any experience with this?
... View more
Labels
- Labels:
-
diag
-
monitoring console
03-26-2021
07:28 AM
none of these answers solves the root problem -- particularly in scenarios where the text log contains a json blob with nested json structure. It is quite confusing that spath command is not available in props.conf -- using spath in search is not an option for things like SIEMs where parsing needs to be done 'automatically' in order to fit into given data models or to map for CIM compliance.
... View more
08-21-2019
10:01 AM
Hello,
Forgive me if this is a silly question but I thought it would be best to directly ask here. Salesforce recently announced they will be Disabling TLS 1.1 support ( https://help.salesforce.com/articleView?id=000321556&type=1&mode=1 ) in September / October.
Our Splunk instance supports teams currently pulling data from Salesforce using this addon. They are proactively concerned about whether this will have an impact on the functioning of this app. I did some searching for tls-related information in the app configs and scripts, but didn't find anything I recognize.
Advice greatly appreciated.
Thank you
... View more
06-13-2019
02:28 PM
1 Karma
While this works, it doesn't address the need of the OP. If you used a [default] stanza in an app that is shared globally, the LOOKUP would be applied to every single index & sourcetype -- which is no bueno.
... View more
07-24-2018
09:19 PM
I would be careful to convert to MB and round after sum'ing, not before
... View more
04-03-2018
06:51 PM
I am in a similar boat and I don't understand your answer... sorry
... View more
02-08-2018
08:15 AM
thanks, this was my problem too 🙂
... View more
01-08-2018
08:43 AM
Hi, I'm wondering if support is planned for Azure File Shares?
We have a file share that contains some csv files. We would like to 'monitor' these files with Splunk using a SAS token, the same way you can monitor a file in a storage blob container. (Mounting the file share is not a viable solution in this case, the environment is dynamic and SAS tokens are refreshed frequently).
Thank you
... View more
Labels
- Labels:
-
troubleshooting
01-05-2018
06:53 AM
A little late to answer your question, but the sparklines are rendering -- it's just that it's setting the min value to whatever the data's value is, which in this case is a a constant -- so it 'draws' a null straight line.
Try adding something like this to the XML:
<option name="chartRangeMin">0</option>
... View more
11-21-2017
09:34 AM
Hello, I'd like to add my voice to this as I am have the same concern as pkeller.
We don't have the luxury of setting SAS token expiry date 'far in the future' -- it needs to be less than 3 months. Our system is configured to generate a new SAS token one week before the current token expires.
pkeller's solution is a good idea --> If we can have two SAS tokens in each storage account config then when the first one expires/fails the second one will be attempted.
Another big concern is that we need to have a way to update SAS tokens without manually typing.
The Azure Monitor Add-on for Splunk, for instance, connects directly to a keyvault to retrieve SAS tokens -- this is a valuable feature.
... View more
11-21-2017
09:26 AM
This is a question for Microsoft/Azure team, not Splunk.
As far as I know, no -- it doesn't seem to be supported at this time.
... View more
11-10-2017
09:21 AM
2 Karma
Previous answer was a great initial template. I took a try at building upon it to add some functionality to the checkboxes. It depends on what your usecase is, but see below:
var selected = []; // 'selected' is an array that contains the IDs of every checkbox that the user selects.
$(document).on('click', '.customcheck', function() {
if($(this).children("i").css("display") == "none")
{
// Do this if the box is going from unchecked to checked:
$(this).children("i").css("display", "inline");
selected.push($(this).children("i").prop("id"));
} else {
// Do this if the box is going from checked to unchecked:
$(this).children("i").css("display", "none");
var index = selected.indexOf($(this).children("i").prop("id"));
if (index > -1) {
selected.splice(index, 1);
}
}
});
require([
"splunkjs/mvc",
"splunkjs/mvc/utils",
"splunkjs/mvc/tokenutils",
"underscore",
"jquery",
"splunkjs/mvc/simplexml",
"splunkjs/mvc/layoutview",
"splunkjs/mvc/simplexml/dashboardview",
"splunkjs/mvc/simplexml/dashboard/panelref",
"splunkjs/mvc/simplexml/element/chart",
"splunkjs/mvc/simplexml/element/event",
"splunkjs/mvc/simplexml/element/html",
"splunkjs/mvc/simplexml/element/list",
"splunkjs/mvc/simplexml/element/map",
"splunkjs/mvc/simplexml/element/single",
"splunkjs/mvc/simplexml/element/table",
"splunkjs/mvc/simplexml/element/visualization",
"splunkjs/mvc/simpleform/formutils",
"splunkjs/mvc/simplexml/eventhandler",
"splunkjs/mvc/simplexml/searcheventhandler",
"splunkjs/mvc/simpleform/input/dropdown",
"splunkjs/mvc/simpleform/input/radiogroup",
"splunkjs/mvc/simpleform/input/linklist",
"splunkjs/mvc/simpleform/input/multiselect",
"splunkjs/mvc/simpleform/input/checkboxgroup",
"splunkjs/mvc/simpleform/input/text",
"splunkjs/mvc/simpleform/input/timerange",
"splunkjs/mvc/simpleform/input/submit",
"splunkjs/mvc/searchmanager",
"splunkjs/mvc/savedsearchmanager",
"splunkjs/mvc/postprocessmanager",
"splunkjs/mvc/simplexml/urltokenmodel",
"splunkjs/mvc/tableview"
],
function(
mvc,
utils,
TokenUtils,
_,
$,
DashboardController,
LayoutView,
Dashboard,
PanelRef,
ChartElement,
EventElement,
HtmlElement,
ListElement,
MapElement,
SingleElement,
TableElement,
VisualizationElement,
FormUtils,
EventHandler,
SearchEventHandler,
DropdownInput,
RadioGroupInput,
LinkListInput,
MultiSelectInput,
CheckboxGroupInput,
TextInput,
TimeRangeInput,
SubmitButton,
SearchManager,
SavedSearchManager,
PostProcessManager,
UrlTokenModel,
TableView
) {
var RangeMapIconRenderer = TableView.BaseCellRenderer.extend({
canRender: function(cell) {
// Only use the cell renderer for the Select field
return (cell.field === 'Select');
},
render: function($td, cell) {
if(cell.field === 'Select')
{
//console.log("cellData: ", cell);
var cellvalue = cell.value;
// This is to handle page changes. If the user selects a box, goes to next table page, then goes back, it rechecks that box to maintain history.
if(selected.includes(cellvalue))
{
$td.html('<label class="checkbox"><a href="#" data-name="splunk_web_service" class="btn customcheck"><i id="'+cellvalue+'" class="icon-check" style="display: inline;"></i></a></label>');
} else {
$td.html('<label class="checkbox"><a href="#" data-name="splunk_web_service" class="btn customcheck"><i id="'+cellvalue+'" class="icon-check" style="display: none;"></i></a></label>');
}
}
}
});
mvc.Components.get('tableid').getVisualization(function(tableView){
// Register custom cell renderer
tableView.table.addCellRenderer(new RangeMapIconRenderer());
// Force the table to re-render
tableView.table.render();
});
}
);
In our case, the next step would be to add a submit button that would trigger something to happen based on the values stored in the 'selected' array.
... View more
11-01-2017
11:06 AM
Great detailed answer. I tend to simply throw relevant tokens into the title or subtitle bar of each panel while developing. Any tokens that aren't set should be obvious.
... View more
10-17-2017
11:09 AM
Some JavaScript intervention could be made to force the chart to redraw when tokens are updated. Wondering if this is the path you took.
... View more
08-16-2017
12:10 PM
Thanks for this! Having the same issue. Hopefully SIEM Connector will help us out too.
... View more