Activity Feed
- Got Karma for Re: Reload transforms.conf without restarting splunk. 06-04-2023 11:45 PM
- Karma Re: How to change advance XML to simple xml ? for Ayn. 06-05-2020 12:46 AM
- Karma Re: Splunk will not start and is waiting for config lock for yannK. 06-05-2020 12:46 AM
- Karma Re: case: defaulting to "value" rather than NULL for sowings. 06-05-2020 12:46 AM
- Karma Re: Will | extract reload=true command refresh everything in props.conf? for kristian_kolb. 06-05-2020 12:46 AM
- Karma Re: Will | extract reload=true command refresh everything in props.conf? for sideview. 06-05-2020 12:46 AM
- Karma Re: nothing happened splank doesn't start for RicoSuave. 06-05-2020 12:46 AM
- Karma Re: nothing happened splank doesn't start for tissparkle. 06-05-2020 12:46 AM
- Karma Re: Creating a Matrix/Grid for kristian_kolb. 06-05-2020 12:46 AM
- Karma Re: Distributed search performance for jerdmann. 06-05-2020 12:46 AM
- Karma Distributed search performance for jerdmann. 06-05-2020 12:46 AM
- Karma Re: Shared realtime searches possible? for yannK. 06-05-2020 12:46 AM
- Karma Re: Where do I start for passing. 06-05-2020 12:46 AM
- Karma Re: Where do I start for cpeteman. 06-05-2020 12:46 AM
- Karma Re: Combining Multivalues together inside a field for cphair. 06-05-2020 12:46 AM
- Karma Re: Chart Overlay and Different Graph Type for jonuwz. 06-05-2020 12:46 AM
- Karma Re: How to delete duplicate events? for _d_. 06-05-2020 12:46 AM
- Karma Re: Test Email in Splunk for gooza. 06-05-2020 12:46 AM
- Karma Re: concatenating fields at search time in props.conf and/or transforms.conf for dart. 06-05-2020 12:46 AM
- Karma Re: splunkd is at 100% cpu, lag in indexing for oreni. 06-05-2020 12:46 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 | |||
4 | |||
0 | |||
0 | |||
1 | |||
2 | |||
0 | |||
0 | |||
3 | |||
0 |
We just encountered the same problem after upgrading from Splunk 5 to Splunk 6.1. We overcame the issue by commenting out the [sslconfig] stanza in server.conf and restarting splunkd. This forces Splunk to generate a new SSL password and all checks passed on start up.
... View more
06-03-2014
01:19 AM
Hi,
If an extract reload isn't working for you, try doing a debug refresh (see 3rd answer for reference).
Cheers,
Matt.
... View more
10-17-2013
05:39 AM
Hi thanks for your comments. It's just as I thought then.. I'll use your recommendations for your setup 🙂
... View more
10-17-2013
03:54 AM
Hi all,
We currently have 4 indexers and 2 search heads running on VMs. We have two more physical servers on their way with faster disk which we will use as indexers. The plan is to use the two physical servers to index the data and store hot + warm buckets and the 4 indexers we have currently will store the cold data.
Firstly, would anyone recommend this type of setup?
Secondly, how do you configure the warm+hot indexers to load balance the cold data across the other 4 indexers? Looking in the documentation I can see that in the indexes.conf file examples (http://docs.splunk.com/Documentation/Splunk/5.0.5/Admin/Indexesconf) that you can specify a "volume", but this only seems to be one server and no more than that...
... View more
10-16-2013
02:32 AM
OK. If you have an automated way (we use blade logic), you can set up a job to remove the inputs.conf and outputs.conf files from your forwarders and add a deploymentclient.conf file with the details of your deployment server (see splunk docs), then trigger a restart. If you don't have an automated way to do this, you will have to do the same thing manually... 😞
... View more
10-15-2013
05:11 AM
What operating system are your forwarders running on? Do you have an automated way of installing the forwarders? i.e. how did you install on 500 servers in the first place?
... View more
10-15-2013
01:42 AM
There's no easy way to edit system/local using the deployment server. You will have to manually delete the inputs.conf and outputs.conf files from system/local and point your forwarder to your deployment server (by editing the deploymentclient.conf file) and restarting Splunk.
From there, you can edit the serverclass.conf file on your deployment server (which will store all of the names of your servers which has forwarders on them.)
Then you can create a simple app in etc/deployment-apps consisting of an inputs.conf and outputs.conf file (similar to what you already had on your forwarder, but you will be able to control this remotely without messing around with the forwarder).
To make sure the forwarder uses IP address, use connection_host=IP as an option for your [WinEventLog:Security] stanza in the inputs.conf file in your app.
Once the app has been created, you will use the "splunk reload deploy-server" command to send the app to your forwarder.
... View more
10-11-2013
06:51 AM
We FTP our Mainframe logs every 5 minutes to a text file on a heavy forwarder. The logs are forwarded on from there and load balanced across our indexers.
... View more
10-03-2013
01:43 AM
Thank you. I would be very grateful.
... View more
09-26-2013
03:44 AM
4 Karma
Hi all,
I have an iFrame which is embedded in my own website hosted by Sharepoint. All was working fine until I upgraded from 5.0.4 to 5.0.5. The iFrame shows the following error:
I've had a look around and found this is due to X-Frame-Options SAMEORIGIN which is something to do with blocking iFrames from being embedded.
I have tried this in all browsers and am getting the same problem each time.
Any ideas how to overcome this?
... View more
09-23-2013
02:57 AM
It works for me too. I had to remove the authorize.conf file that was already in system/local, but it worked in the end.
... View more
09-23-2013
01:23 AM
I did it by setting up hMail server and running a VBScript to pick up all the PDF attachments and save them to disk. I did raise an enhancement request with Splunk regarding this, but haven't heard anything. With Splunk 6 coming out in October, I hope they have added this feature!
... View more
09-17-2013
01:29 AM
You need to replace "yoursplunkserver" with your server address. If you are using a local version of splunk, replace "yoursplunkserver" with "localhost".
So, http://localhost:8000/en-GB/debug/refresh
... View more
09-16-2013
03:20 AM
22 Karma
Hi Jrodriguez.
You can reload any number of config files at index time using the debug refresh endpoint in Splunk. I use this all the time when I make changes to props.conf.
You can view all of the endpoints by typing the following into your browser:
http://yoursplunkserver:8000/en-GB/debug/refresh
and to explicitly reload the transforms.conf file, use the following:
http://yoursplunkserver:8000/en-GB/debug/refresh?entity=admin/transforms-lookup
for new lookup file definitions that reside within transforms.conf
http://yoursplunkserver:8000/en-GB/debug/refresh?entity=admin/transforms-extract for new field transforms/extractions that reside within transforms.conf
Hope this helps!
... View more
09-11-2013
08:25 AM
Hi Chris,
http://docs.splunk.com/Documentation/Splunk/5.0.4/AdvancedDev/3rdParty
All can be found in the above link..
Thanks,
Matt.
... View more
09-10-2013
07:17 AM
Hi Bruce,
I'm currently having the same issues. I'm not sure what the issue is with our VM's either. Did you get anywhere with yours?
... View more
09-10-2013
05:35 AM
5 Karma
I would like to say...
Thank you so much for this answer!!!
I used the following search to work out the duplicates:
index= | streamstats dc(info_search_time) as count by _time | where count!=1 | eval delete_id=_cd."|".index."|".splunk_server | stats count by delete_id | fields - count | outputcsv dupes.csv
and the following search to delete them:
index= | eval delete_id=_cd."|".index."|".splunk_server | search [|inputcsv dupes.csv | format "(" "(" "OR" ")" "OR" ")"] | delete
... View more
09-05-2013
07:01 AM
You can also use post process with this to optimize even further!
... View more
09-03-2013
06:59 AM
I'm not sure, but I think you need to add autoRun="True" to your Search module.
So module name="Search" autoRun="True"
... View more
08-28-2013
08:53 AM
A couple of ways I have done this in the past. We are currently using the automated option and is working for us. We are able to produce daily, weekly and monthly reports in Excel format using templates.
Manual
Using the export option from the
search bar (after the search has
completed) or use a saved search
where the CSV file is sent via
e-mail.
Dump the contents of the CSV file into the template you created
and it will be mapped to display the
data in the correct way. (Look up
"excel link values")
OR
Automated
Install a free mail server (hMail server).
Point Splunk to send emails to the mail server.
Attach a VBScript to the mail server to scan each email for a CSV attachment and save it.
A VBScript is run on a CRON job to copy the CSV file to the Excel template (stored locally).
The template you created will be mapped to display the data in the correct way. (Look up "excel link values")
The file will be saved locally, but you could always configure it to be sent to an e-mail recipient.
... View more
08-22-2013
03:57 AM
From my understanding of your question, would it just be like this?
sourcetype=data | chart sum(purchases), avg(purchases) by username
... View more
08-08-2013
01:22 AM
Hi Dimitri,
Thanks for your reply. I have since found that the issue is with the high CPU usage. There are a lot of buckets over 6 months old, so Splunk takes time and CPU to process these and the indexing queue backs up and fills in no time, so the indexer blocks all incoming data on port 9997 until the buckets have been frozen.
... View more
08-05-2013
08:19 AM
I've tried to add a 6 month retention policy to the main index. As the main index is already defined in the default indexes.conf, I only need to specify the following in the local indexes.conf:
[main]
frozenTimePeriodInSecs=15552000
After I've restarted my indexers for the configuration to take affect, the data stops being indexed into main.
Anyone got any ideas as to where I'm going wrong?
Cheers.
... View more