What a fantastic idea to bundle up everything for a nice and smooth implementation, makes so much sense, and will further assist in raising the security maturity of our customers!!
... View more
You can change via server.conf, CLI or Splunk Web 🙂
https://docs.splunk.com/Documentation/Splunk/7.3.0/Indexer/Setlimitsondiskusage
remember to select your correct version of Splunk on the top right
... View more
I would add the server.conf stanza on the NAS instance, and possibly look into the below if it doesn't resolve the issue.
https://docs.splunk.com/Documentation/Splunk/7.3.0/DistSearch/Manageconfigurationchanges
... View more
Hello ramprakash,
If it won't affect your performance, you can add a [diskUsage] stanza in server.conf, right now your minFreeSpace is 5Gb, you can lower that threshold to 1Gb or you can add more storage.
Below will help remove the error, and show the instance as healthy, but won't address the storage issue, if there is one.
$SPLUNK_HOME/etc/system/local/server.conf
[diskUsage]
minFreeSpace = 1000
Cheers,
... View more
You should consider reworking your search using the timechart command instead of table and stats:
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Timechart?r=searchtip
Once this is done, Returned statistics can be displayed as a visualization via the GUI, you can find information about that here :
https://docs.splunk.com/Documentation/Splunk/7.3.0/SearchTutorial/Chartasareport
... View more
Hello,
Try here : https://docs.splunk.com/Documentation/ES/5.3.0/Install/DeploymentPlanning
Also a best practice to utilize CIM to normalize data, I would install it.
Cheers,
... View more
It can generate certs by default, and they expire after 3 years.
https://docs.splunk.com/Documentation/Splunk/7.3.0/Security/Aboutsecuringdatafromforwarders
... View more
Yes, and you can delete the old forwarder directory once you apply all the old configs to the new, and get the data forwarding to indexers.
... View more
Hello,
Email Splunk Education in your respective region and request to re-enroll.
Americas: education_amer@splunk.com
Europe: education_emea@splunk.com
Asia/Japan/Australia: education_apac@splunk.com
Cheers,
... View more
I recommend using this product (Splunk Enterprise) for the fundamentals I course, it gives you a 60 day trial vs. 14 days with Splunk Cloud
download and install from here :
https://www.splunk.com/en_us/download/splunk-enterprise.html
If you prefer to use Splunk Cloud, it sounds like you may not have added any data, here is the documentation on how to accomplish that.
https://docs.splunk.com/Documentation/SplunkCloud/7.2.6/Data/Getstartedwithgettingdatain
Cheers,
... View more
Hello,
Save a copy of inputs.conf from the current instance, re-install the forwarder and place the saved copy of inputs.conf in the correct directory.
I would also adjust the Ulimits to the recommended settings.
Cheers,
... View more