Activity Feed
- Got Karma for creating a scatterplot with time on the x-axis. 11-29-2023 05:24 AM
- Karma Trying to apply the Splunk Add-on for Microsoft Hyper-V to an indexer cluster bundle, why are we getting "Not URI Encoded" errors? for jonesnadiam. 06-05-2020 12:48 AM
- Got Karma for Re: How to integrate SAML authentication for Splunk Cloud?. 06-05-2020 12:48 AM
- Got Karma for creating a scatterplot with time on the x-axis. 06-05-2020 12:48 AM
- Got Karma for creating a scatterplot with time on the x-axis. 06-05-2020 12:48 AM
- Got Karma for creating a scatterplot with time on the x-axis. 06-05-2020 12:48 AM
- Got Karma for creating a scatterplot with time on the x-axis. 06-05-2020 12:48 AM
- Karma Re: Is anyone aware of the availability of the geometric mean stats in Splunk? for aljohnson_splun. 06-05-2020 12:47 AM
- Karma Re: Why does splunk need to be installed as root? for jrodman. 06-05-2020 12:47 AM
- Karma Re: How to configure props.conf and transforms.conf to filter out events from web logs before getting indexed? for yannK. 06-05-2020 12:47 AM
- Karma Re: Where to install Seach Activity app? for David. 06-05-2020 12:47 AM
- Got Karma for Why does splunk need to be installed as root?. 06-05-2020 12:47 AM
- Got Karma for Re: Why am I getting "Error fetching event from search peer" when searching for a specific sourcetype?. 06-05-2020 12:47 AM
- Got Karma for Re: Why am I getting "Error fetching event from search peer" when searching for a specific sourcetype?. 06-05-2020 12:47 AM
- Karma Re: Field extraction with multiple matches per line for Ayn. 06-05-2020 12:46 AM
- Karma dispatch.finalizeRemoteTimeline taking a long time? for dshpritz. 06-05-2020 12:46 AM
- Karma Re: dispatch.finalizeRemoteTimeline taking a long time? for abhijitmishra. 06-05-2020 12:46 AM
- Karma Re: Multiple key value pair extraction for hazekamp. 06-05-2020 12:45 AM
- Posted Re: creating a scatterplot with time on the x-axis on Splunk Search. 03-14-2017 08:21 PM
- Posted creating a scatterplot with time on the x-axis on Splunk Search. 03-14-2017 03:01 PM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
5 | |||
1 |
03-14-2017
08:21 PM
Good idea, but sadly that doesn't work either. On the chart, all points are assigned a value of _time=0. Would post a screenshot, but already exceeded my two img upload limit for this post.
... View more
03-14-2017
03:01 PM
5 Karma
I'm looking to create a multi-series scatter plot where time is on the x-axis.
An example would be something like this:
Attempts to do this in splunk are failing. Given the format requirements: ... | table marker_name_field x-axis_field y-axis_field
In the first attempt, using _time, all points are assigned an x-value of 0, like splunk can't understand the timestamp in its native/textual format. (see example below)
Using the timestamp in epoch format works in that it will correctly display points along the x-axis, but having a timestamp in that format is not human interpretable, so is not particular useful or viable as an option. (see example below)
Short of using D3 to create a custom viz, is there something I'm missing, or are Splunk's native viz capabilities unable to create this kind of chart?
... View more
04-13-2016
01:03 PM
1 Karma
1) SAML2.0 is pretty standard. What makes Splunk support only specific Identity Providers rather than all the standard SAML2.0 implementations out there?!
Every vendors implement portion of SAML 2.0 and leave out the rest. We need to test / ensure that the IdP works with our code base. This will help us to meet our cloud related SLA to our customers.
2) Does Splunk Cloud support deep link URLs?
Yes we do, We track the user’s link(example – a saved search link etc.) using the ‘relayState’ parameter of SAML. When a user logs in using SAML, we sent the user’s link to the IDP as a part of the SAML request in a SP initiated workflow. Once the user is authenticated, we get the relayState back in the SAML response and we redirect the user to the link.
3) Which default SAML binding does Splunk require HTTP POST Or REDIRECT Or ARTIFACT?! Does it support other bindings too?
We support POST (6.3/6.4), REDIRECT (6.4.1)
4) How can I get the sp metadata from Splunk Cloud?
Log in as a local user. Navigate to splunkweb’s endpoint - ‘https://:/en-us/saml/spmetadata' endpoint. This has Splunk’s SP metadata and you can copy the entire xml out. Note:- If saml is not configured, a template entity id called ‘SplunkentityId’ is generated as a placeholder. This entity id can be changed when SAML is configured.
#thankyoueng
... View more
01-15-2016
04:46 PM
One way might be to have a periodic dump of Active directory users into a lookup file using the SA for LDAP. The dump would include all relevant information like the domain, username, and first & last names for the users. You could then use a lookup to resolve the field in the logs to what's in AD.
Make sense? Can go into more detail if needed.
... View more
11-14-2014
12:49 PM
1 Karma
The docs mention installs need to be done as root (but don't really explain why) - http://docs.splunk.com/Documentation/Splunk/6.2.0/Installation/RunSplunkasadifferentornon-rootuser
Some answers refer to the need to provide, to the user running splunk, access to /dev/urandom, though it isn't clear why that's necessary (encryption?) - http://answers.splunk.com/answers/49153/install-splunk-as-non-root-user.html
What aspects of the installation of splunk require root privileges? For the more security conscious sysadmins out there, being able to install splunk without opening the root kimono would be much more preferable.
BTW, as a test, I installed splunk as a non-root user (on a host where splunk was already installed), then brought up this new instance as that user, and verified there weren't any errors during startup. I also verified that i could login to the UI and do basic navigation. So at first glance, it looks like the root privileges aren't a requirement. Then again, this was far from a thorough shake-out test, and could've missed something.
... View more
09-30-2014
02:04 PM
2 Karma
Are any results returned at all by that search? Or do you only see that error when looking at earlier time buckets in the timeline? And is this a distributed search environment?
It could be that you're running up against the remote_timeline_max_size_mb property in limits.conf. This controls how much of the data returned by the search peer will actually get stored in the search's dispatch directory. The default is 100mb, and if the peer returns more than that, splunk will only actually store the latest 100mb worth. For all earlier events, when attempting to look at them by clicking on a bucket in the timeline, you'll get that message.
... View more