Activity Feed
- Got Karma for Re: no data for cpu.sh *NIX app. 09-22-2021 12:48 PM
- Karma Re: no data for cpu.sh *NIX app for rturk. 06-05-2020 12:46 AM
- Karma Re: no data for cpu.sh *NIX app for araitz. 06-05-2020 12:46 AM
- Got Karma for Re: no data for cpu.sh *NIX app. 06-05-2020 12:46 AM
- Got Karma for Re: no data for cpu.sh *NIX app. 06-05-2020 12:46 AM
- Got Karma for Re: no data for cpu.sh *NIX app. 06-05-2020 12:46 AM
- Got Karma for Re: no data for cpu.sh *NIX app. 06-05-2020 12:46 AM
- Got Karma for Re: no data for cpu.sh *NIX app. 06-05-2020 12:46 AM
- Got Karma for Re: no data for cpu.sh *NIX app. 06-05-2020 12:46 AM
- Got Karma for Re: no data for cpu.sh *NIX app. 06-05-2020 12:46 AM
- Posted Re: How to restart a remote Windows service from a Splunk search alert script? on Alerting. 10-22-2014 11:08 AM
- Posted How to restart a remote Windows service from a Splunk search alert script? on Alerting. 10-21-2014 10:51 AM
- Tagged How to restart a remote Windows service from a Splunk search alert script? on Alerting. 10-21-2014 10:51 AM
- Tagged How to restart a remote Windows service from a Splunk search alert script? on Alerting. 10-21-2014 10:51 AM
- Tagged How to restart a remote Windows service from a Splunk search alert script? on Alerting. 10-21-2014 10:51 AM
- Tagged How to restart a remote Windows service from a Splunk search alert script? on Alerting. 10-21-2014 10:51 AM
- Tagged How to restart a remote Windows service from a Splunk search alert script? on Alerting. 10-21-2014 10:51 AM
- Posted scheduling best practices question on Alerting. 06-06-2014 12:43 PM
- Posted Re: Scheduled Real-time AlertsTerminating on Alerting. 06-05-2014 02:01 PM
- Posted Re: Splunk 6.1.1 upgrade from 6.0.3 Windows Splunk license agreement was not accepted. If installing silently, please pass AGREEMENTOLICENSE=Yes on Getting Data In. 06-02-2014 08:51 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 |
10-22-2014
11:08 AM
I had tried passing parameters to the script, but I was unsuccessful.
... View more
10-21-2014
10:51 AM
I want to restart a remote Windows service from a Splunk search alert script. How do I pass the server name to the script? Is it possible using PowerShell? Do I need to use the same service account running the splunkforwarder service on the client as is running on the SPlunk search head.
... View more
06-06-2014
12:43 PM
Yes, I read the http://docs.splunk.com/Documentation/Splunk/6.1.1/Alert/Definescheduledalerts document, but I'm still somewhat confused with regard to the following:
Coordinate the alert's search schedule with the search time range. This prevents situations where event data is accidentally evaluated twice by the search (because the search time range exceeds the search schedule, resulting in overlapping event data sets), or not evaluated at all (because the search time range is shorter than the search schedule).
Schedule your alerting searches with at least 60 seconds of delay. This practice is especially important in distributed search Splunk implementations where event data might not reach the indexer precisely at the moment when it is generated. A delay ensures that you are counting all of your events, not just the ones that were quickest to get indexed.
So is this basically telling me I should not do less than 6 minute searches (allowing for 60sec delay)? Essentially. I'd like to know if something occurred in the past 5minutes or would the following work?
earliest: -5m@m
latest: now
cron expression: */5 * * * *
... View more
06-05-2014
02:01 PM
I've noticed the same problem. We just upgraded from 6.03 to 6.1.1. We have 7 realtime jobs so I wouldn't think that would overload the system.
... View more
06-02-2014
08:51 AM
Thanks this helped. We also had a few where we had to upgrade to 6.0.3 and then to 6.1.1.
... View more
06-02-2014
08:48 AM
Thanks this helped. We also had a few where we had to upgrade to 6.0.3 and then to 6.1.1.
... View more
05-29-2014
07:08 AM
We were initially trying to upgrade from 6.0.3 to 6.1.1. However, we keep receiving the following message, "Splunk license agreement was not accepted. If installing silently, please pass AGREEMENT LICENSE=Yes".
When we try to uninstall Splunk from Add/Remove Programs we receive the same error as when we try to run the upgrade.
The service is still installed, but will not start and we receive the following error, "Windows could not start the SplunkForwarder service on Local Computer. Error 3: The system cannot find the path specified."
We tried deleting the SplunkForwarder directory, but that doesn't help either.
... View more
10-23-2013
02:46 PM
Sorry applog, syslog, seclog were short for: WinEventLog:Application, WinEventLog:Security, WinEventLog:System
No its a linux Deployment Server.
Splunk version 5.0.1
... View more
10-23-2013
12:53 PM
We started using Splunk deployment server after some Windows servers already had the universal forwarder installed. However, it seems some servers were installed without the Splunk UniversalForwarder being configured correctly. Currently the $decideOnStartup "host" is reporting performance metrics, but I don't see any applog, seclog, or syslog data. I know that doesn't mean the server isn't reporting any data for the logs, I just don't have any data since the Splunk history was truncated to 35 days ago.
Is there an easy way to determine what server has the messed up configuration?
At the moment, I think I will be comparing the "All Forwarers" report from the Deployment Monitor Application and
... View more
10-18-2013
07:40 AM
I have the search and alert working and my script will run if I execute it locally, but since the script is running from the Heavy Forwarder I can't get the application(s) to start.
runas /profile /env "C:\Program Files (x86)\Notepad++.exe" >> test-restart.txt
runas /profile /env "C:\Program Files (x86)\putty\putty.exe" >> test-restart.txt
I was trying to get these simple applications to run before working on the production applications. I also wanted to email the log success or failure of the application(s) start.
I did run the following:
index=windows host=testserver sourcetype="WinEventLog:Application" EventCode=1000 Type=Warning "Faulting Application name: Test123" | runshellscript Test-Application-restart.bat
Here was the output of the above search:
External search command 'runshellscript' returned error code 1. Script output= "ERROR "Missing arguments to operator 'runshellscript', expected at least 10, go 2." "
... View more
09-30-2013
09:16 AM
splunkd.log
ERROR ExecProcessor - message from ""c:\Program Files\SplunkUniversalForwarder\bin\splunk-perfmon.exe"" splunk-perfmon - Unable to add counter '\Memory(*)\% Committed Bytes In Use' error 0xc0000bb9\n
ERROR ExecProcessor - message from ""c:\Program Files\SplunkUniversalForwarder\bin\splunk-perfmon.exe"" splunk-perfmon - Unable to add counter '\Memory(*)\Available MBytes' error 0xc0000bb9\n
ERROR ExecProcessor - message from ""c:\Program Files\SplunkUniversalForwarder\bin\splunk-perfmon.exe"" splunk-perfmon - Unable to add counter '\Memory(*)\Committed Bytes' error 0xc0000bb9\n
... View more
09-16-2013
12:20 PM
BenjaminWyatt:
inputs.conf snippet...
Memory
[perfmon://Memory]
counters = % Committed Bytes In Use;Available MBytes;Committed Bytes
disabled = 0
interval = 300
object = Memory
_TCP_ROUTING = mysplunkindexers
index = myindexname
... View more
09-16-2013
10:48 AM
I have a Windows 2003 Server that is able to report memory stats when running the Windows performance monitor locally on the server. Unfortunately I do not see any data in Splunk for memory for this particular system. All of the other Windows 2003 Servers are displaying memory stats.
... View more
09-13-2013
09:11 AM
Yes, there is a Deployment App and it has a search for "Forwarder Warnings/Missing Forwarders (A missing forwarder has connected at some point in the past, but has not connected in the last 24 hours.). Unfortunately if the system has never had Splunk installed it won't be in the results. Thank you for the reminder as the app has been helpful as well.
... View more
09-12-2013
01:46 PM
For Windows servers, I send a test event to app, sec, sys logs: eventcreate /s servername /t Warning /ID 1000 /L APPLICATION /D "Testing splunk"
... View more
09-12-2013
10:18 AM
We have several Windows servers with the light SplunkUniversalForwarder installed. Recently we discovered a few servers weren't reporting a sourcetype. I want to verify that each of the servers with a light-SplunkUniversalForwarder installed is sending the appropriate data. I have tried to manually check each system, but that is very tedious and time consuming. If a system isn't reporting a sourcetype then I would like to be alerted or report emailed and then I can troubleshoot more in-depth.
Basically I want to know if all systems are reporting any data for the following:
Perfmon:FreeDiskSpace
Perfmon:LocalNetwork
Perfmon:Memory
Perfmon:CPUTime
WinEventLog:System
WinEventLog:Application
WinEventLog:Security
Does anyone have any suggestions?
... View more
09-18-2012
02:56 PM
I was able to get reset key from Rob, but now when I go to Deployment Monitor > License Report
Usage Summary
Peak daily usage in last 30 days: 0.06 GB
Average daily usage across all days in last 30 days: 0.06 GB
Average usage across top 5 days in last 30 days: 0.06 GB
The Splunk on Splunk Metrics shows the same .06Gb
So now I'm really confused.
... View more
09-17-2012
02:13 PM
I was testing Splunk App for *nix before putting it into production. We were consistently getting 30-40Mb/day, but while I was out of the office (14 days), the usage went over the 500Mb limit. I'm trying to determine what caused the overage and by how much before moving to production and having even bigger problems if we go over our 10Gb license.
Apps > Search > Status > Index Activity > Indexing
is displaying less than 100Mb per day.
Any ideas?
... View more
07-10-2012
02:52 PM
8 Karma
I was logged in as root.
It looks like my problem was that the sysstat package wasn't installed, although I thought I had verified that the paackage was installed and ran the cpu.sh.
I was missing the sar application.
... View more
07-09-2012
02:08 PM
Running Splunk TA on SLES 11 SP1. I ran cpu.sh manually and did not receive any errors. I verified the script is enabled in inputs.conf. There is no data for sourcetype=cpu.
Shows stats per CPU (useful for SMP machines)
[script://./bin/cpu.sh]
sourcetype = cpu
source = cpu
interval = 300
index = os
disabled = 0
... View more
07-06-2012
09:31 AM
Has anyone seen an issue increasing the intervals for TA running SUSE? When I increase the intervals, the *nix 4.5 app stops updating the graphs.
Here are the intervals I changed:
vmstat- 300
iostat- 600
ps- 300
top- 300
protocol- 300
lsof- 600
df- 600
cpu- 300
fschange- 600
However CPU Overview, Memory Overview, Disk Overview don't work for last 15 mins or last 60 mins. I don't know if there isn't enough data points for the graph? I edited the CPU overview "CPU consumption by command" graph to 2 hours and the graph works. Anything less than 120 mins (even 90 mins) and the graph does not fill in.
... View more