Activity Feed
- Karma Re: Using Splunk with NiFi for cbutler_isenpai. 08-25-2023 06:04 AM
- Karma Re: It is possible to "tag" all data coming into a particular HEC token? for MuS. 10-21-2020 10:30 AM
- Karma Re: Why is the Universal Forwarder also sending internal logs when only told to send certain data to different indexer via _TCP_ROUTING in inputs.conf? for dineshraj9. 09-24-2020 10:03 AM
- Karma Re: How to edit my search to track event counts by Index/Sourcetype to see when data is no longer being received? for mattymo. 06-05-2020 12:48 AM
- Got Karma for Splunk Search Head Cluster 6.5.3 issue - cluster members stop running scheduled searches. 06-05-2020 12:48 AM
- Karma Re: sorting by date timestamp not working as expected for gfuente. 06-05-2020 12:47 AM
- Karma How to configure Chrome as a search engine for Splunk queries? for oxnard. 06-05-2020 12:47 AM
- Got Karma for Re: Can Splunk handle indexing a CSV file containing more than 6000 fields/columns?. 06-05-2020 12:47 AM
- Got Karma for Re: sorting by date timestamp not working as expected. 06-05-2020 12:47 AM
- Got Karma for Re: sorting by date timestamp not working as expected. 06-05-2020 12:47 AM
- Got Karma for Re: Connection errors to heavy forwarders. 06-05-2020 12:46 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 | |||
0 | |||
0 | |||
0 | |||
1 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 |
03-22-2022
06:07 AM
Dear Oscarminassian, I am facing the same issue of missing lines. Did you find any solution for the missing events issue? If yes, Could you please share the same here. Thanks Ratan
... View more
09-22-2021
01:23 PM
I was able to get the agent and figure it out. Just syslog on the backend. Thanks Ed
... View more
04-21-2021
03:17 PM
i turned the debug logs on but that just confirmed Splunk is ignoring the files even though the paths are present in list monitor. Just opened a case. Thanks
... View more
09-30-2020
08:52 AM
Hi, yes I got it to work. Try: Name Node = maprfs:/// Since MapR use Yarn the important flags are vix.yarn.resourcemanager.address vix.yarn.resourcemanager.scheduler.address
... View more
07-07-2020
03:12 PM
Doug are you saying we can now configure more than one FMC in the TA? We have 13 FMCs and I dont want to have to manage 13 HFs to support this use case. Would much prefer to load it all into one or two TAs. We have tried to use the Encore command line client, but it is not super stable and disconnects a lot. What you have configured in the TA is much more stable. Thanks!
... View more
01-25-2018
11:41 AM
I would question why you want it done at index time. It rarely makes a performance improvement (In fact more often makes things worse) and takes more disk space.
But if you are sure you want to try this on your development system use the above linked answer but replace the REPORT-xyz in props.conf with TRANSFORMS-xyz and add WRITE_META = true to the transforms.conf stanza.
... View more
06-16-2017
08:17 AM
for anyone interested you can get this information by turning on access to syslog_transaction table in the SN add-on inputs section under inputs. Ne warned it is a lot of data and you can only pull 1000 events per collection interval so plan accordingly.
... View more
05-29-2017
06:46 PM
Try removing the members, cleaning them, initialize them and rejoining them:
Removal:https://docs.splunk.com/Documentation/Splunk/6.5.2/DistSearch/Removeaclustermember
Clean/initialize/Join:http://docs.splunk.com/Documentation/Splunk/6.5.2/DistSearch/Addaclustermember#Add_a_member_that_was_previously_removed_from_the_cluster
... View more
06-13-2017
11:46 PM
Hi, Roles are defined in Splunk_TA_VMWare and you can refer this link https://docs.splunk.com/Documentation/VMW/3.3.2/Installation/DownloadandinstalltheSplunkAppforVMware and ensure that you have deployed all required component on specific instances. And also make sure that you have deployed the same version of apps and addons.
... View more
03-27-2017
03:24 AM
Are you trying to predict or detect anomalies?
Couple of options :
As of MLTK 2.1, you could use the Detect Numeric Outliers with the "Fields to split by" for your customer fields, and use a sliding window too.
If you take a look at the Conf presentations from last year, https://conf.splunk.com/files/2016/slides/building-a-crystal-ball-forecasting-future-values-for-multi-cyclic-time-series-metrics-in-splunk.pdf is pretty awesome.
Are you looking to predict a number of transaction counts and then alert when the residual (actual - predicted/estimated) values differ? you can use the Predict Numeric Fields Assistant with some clever stats by client,dayofweek,hourofday, etc variables. You will have to understand how linear regression works.
... View more
01-30-2017
06:40 AM
Ok sorry i missed that - it becomes a kv pair as it should - so my search
index="skynet" sourcetype="custom_json_indexed" Msg GvuLnDhEXexLaaHmMHSaqQJyozYtFJAarNkkridVbsUHmcZagLNwPrsVvycpKoGsohXgnzyvAbrWLaZalFIasamdiPJwikfEBZraMpugIJaShabvEaidNRJakYjdeEIVKWMvqJDoAIJQcVhgKaISSVLYojjRaHNaSJcywvaaaYsaaassiVtmdBGWlqBEzGtHmqaaVk
become
index="skynet" sourcetype="custom_json_indexed" Msg GvuLnDhEXexLaaHmMHSaqQJyozYtFJAarNkkridVbsUHmcZagLNwPrsVvycpKoGsohXgnzyvAbrWLaZalFIasamdiPJwikfEBZraMpugIJaShabvEaidNRJakYjdeEIVKWMvqJDoAIJQcVhgKaISSVLYojjRaHNaSJcywvaaaYsaaassiVtmdBGWlqBEzGtHmqaaVk "mdc.mdcKeyaippQ"=mdcValueuvCvVphbipWgKdaagITQ
... View more
09-18-2016
06:17 PM
1 Karma
Have you looked at the nmon application for Splunk ? NMON Performance Monitor for Unix and Linux Systems ?
https://splunkbase.splunk.com/app/1753/
It does most of what you are trying to do, and it would be easier than trying to build data models and then accelerating them for the information you require (the nmon app has a number of accelerated data models).
... View more
06-14-2018
11:54 AM
Is it possible to suppress the error per-sourcetype so as not to clutter the logs?
... View more
08-07-2016
02:26 PM
You can hide the index= stuff inside of an eventtype (or a macro ) and then update that KO after the events age out.
... View more
07-22-2016
06:00 AM
ok - that makes sense. I need to define the overall size along with the size for home and cold so data is shifted to cold to account for limits in main storage.
Thanks!
... View more
05-04-2017
02:07 PM
We are having the same problem. What do you mean by "writing a wrapper to execute the PS script and using a script input" as the workaround?
... View more
12-18-2014
11:54 AM
It doesn't appear that you are sending anything to the [serverClass:test] machines. That would make those whitelisted servers think that they should not have anything from the deployment server and will remove anything in the etc/apps directory that would be controlled by the deployment server (under the etc/deployment-apps directory on the deployment server).
You should have a list of apps that you want on the indexer, something like:
[serverClass:test]
whitelist.0 = test*
[serverClass:test:app:appnumber1]
[serverClass:test:app:appnumber2]
The two lines that I added are related to the servers listed in the whitelist because they have the same serverClass:test at the beginning of the definition. when the deployment server is contacted by a whitelisted server, the apps (appnumber1 and appnumber2) will be sent to them. If they change at some point, the deployment server with then send the updated files. If you were to remove one of those apps from the configuration, the server would be told to remove that app by the deployment server.
You can do all the deployment of all the apps at once, it should not make a difference. You just have to get the configuration right.
If you are using clustered indexers, don't use the deployment server for the deployment of the apps to the cluster master, just make your modifications on the cluster master. Then when you apply the cluster-bundle it will distribute to the indexers and then do a nice rolling restart.
... View more
03-22-2016
05:46 PM
1 Karma
issue was with the ESX server hosting the HF - very high iowait was the issue
... View more
02-06-2018
05:28 PM
Hey, Ed.
It sounds like you're monitoring a local directory on a syslog server. Try creating a local/inputs.conf file with the monitor stanza, and only assign sourcetype = syslog:
[monitor:///opt/logs/all_logs]
diabled = false
sourcetype = syslog
Also - make sure the hostname in the ASA is configured correct, as well as this command:
asa(config)#logging device-id hostname
The Add-on should pull out the hostname accurately. This worked for me. I didn't edit transforms or props. Let me know if it works!
Ed (as well)
... View more