Activity Feed
- Posted Re: Configured but Inactive Forwards, inspite of resolving Firewall issue. Why? on Getting Data In. 03-24-2021 10:16 AM
- Posted Trying to monitor local macOS system logs and performance data as remote log from Ubuntu instance on VirtualBox on Getting Data In. 03-21-2021 10:42 AM
- Posted Re: monitor log file macOs on Monitoring Splunk. 03-20-2021 02:34 PM
- Posted Splunk Add-on for Unix and Linux - can't connect to server on All Apps and Add-ons. 03-20-2021 08:20 AM
- Posted Re: Splunk Add-on for Unix and Linux - can't connect to server on Splunk Enterprise. 03-20-2021 08:19 AM
- Posted Re: Is there any way to monitor CPU on Mac OS? on Getting Data In. 03-20-2021 08:18 AM
- Posted Re: Splunk Add-on for Unix and Linux - can't connect to server on Splunk Enterprise. 03-20-2021 08:13 AM
- Posted Splunk Add-on for Unix and Linux - can't connect to server on Splunk Enterprise. 03-20-2021 07:55 AM
- Karma Re: Is there any way to monitor CPU on Mac OS? for twinspop. 03-20-2021 07:11 AM
- Posted Re: Would like to build basic dashboards showing graphs based on the contents of monitored logs on macOS on Monitoring Splunk. 03-19-2021 01:42 PM
- Posted Would like to build basic dashboards showing graphs based on the contents of monitored logs on macOS on Monitoring Splunk. 03-19-2021 01:31 PM
- Karma Re: couldn't send SIGTERM to pid 5632: Operation not permitted for koshyk. 03-19-2021 02:05 AM
- Karma Re: Web server not starting for Vardhan. 03-18-2021 08:07 AM
- Posted Re: Web server not starting on Installation. 03-18-2021 08:06 AM
- Posted Re: Change splunk web server from the default setting of port 8000 to port 8081 on Security. 03-18-2021 06:58 AM
- Posted Re: Cannot get to Splunk Web interface on Installation. 03-18-2021 06:53 AM
- Posted Web server not starting on Installation. 03-18-2021 04:47 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 | |||
0 | |||
0 | |||
0 | |||
0 |
03-24-2021
10:16 AM
But what about universal forwarder? Could you install eventgen add on for universal forwarder? I have tried but no luck. Have looked through several posts and checked everything, still having the forwards inactive. Any help appreciated
... View more
03-21-2021
10:42 AM
I am trying to get my Ubuntu instance on VirtualBox to ingest my mac's system logs and performance data as remote logs. I already installed the add-on for linux and unix and configured the forwarding host as 10.0.2.255:9997 on my Mac and receiving port as 9997 on the Ubuntu instance. I edited the input.config of the add-on for linux and unix and enable all the metrics and put the 'index = mac' on every one of them. I already added the index 'mac' for the admin on the ubuntu instance. However, when I searched 'index = mac' on the ubuntu instance, there is no data. Is there something important that I am missing? Any help would be appreciated as this is really important as this will determine whether I will have the opportunity. Many thanks!
... View more
Labels
03-20-2021
02:34 PM
Why there is nothing happened when I click 'save' for setting of the add-on? I am still trying to figure out how to use the add-on.
... View more
03-20-2021
08:20 AM
Trying to monitor the performance data on MacOS and downloaded Splunk Add-on for Unix and Linux After clicking 'save' for setting on Splunk Enterprise Web, it shows the page that says 'Safari Can't Connect to the Server Safari can't open the page "localhost:8000/en-US/app/Splunk_TA_nix/ta_nix_configuration" because Safari can't connect to the server "localhost".' Please find the attached for reference Any help would be appreicated! Thanks! ref: https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/About https://splunkbase.splunk.com/app/833/ https://lantern.splunk.com/hc/en-us/articles/360048491734-Operating-system-performance-data-
... View more
Labels
- Labels:
-
configuration
-
troubleshooting
03-20-2021
08:19 AM
ref: https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/About https://splunkbase.splunk.com/app/833/ https://lantern.splunk.com/hc/en-us/articles/360048491734-Operating-system-performance-data-
... View more
03-20-2021
08:18 AM
Trying to monitor the performance data on MacOS and downloaded Splunk Add-on for Unix and Linux After clicking 'save' for setting on Splunk Enterprise Web, it shows the page that says 'Safari Can't Connect to the Server Safari can't open the page "localhost:8000/en-US/app/Splunk_TA_nix/ta_nix_configuration" because Safari can't connect to the server "localhost".' Please find the attached for reference Any help would be appreicated! Thanks! ref: https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/About https://splunkbase.splunk.com/app/833/ https://lantern.splunk.com/hc/en-us/articles/360048491734-Operating-system-performance-data-
... View more
03-20-2021
08:13 AM
This is the link to the add-on https://splunkbase.splunk.com/app/833/#/overview
... View more
03-20-2021
07:55 AM
Trying to monitor the performance data on MacOS and downloaded Splunk Add-on for Unix and Linux After clicking 'save' for setting on Splunk Enterprise Web, it shows the page that says 'Safari Can't Connect to the Server Safari can't open the page "localhost:8000/en-US/app/Splunk_TA_nix/ta_nix_configuration" because Safari can't connect to the server "localhost".' Please find the attached for reference Any help would be appreicated! Thanks!
... View more
Labels
- Labels:
-
troubleshooting
03-19-2021
01:42 PM
Is the below page what I am supposed to follow? However, I can't find the OSX after clicking 'Add Data' https://docs.splunk.com/Documentation/InfraApp/2.2.3/Admin/AddDataMacOSX For performance data, I assume I should monitor the cpu, ram, battery usage, etc. for creating meaningful dashboards? However, are there any logs for this performance data on macOS? If not, how should I get this data in from maybe Activity Monitor? Thanks!
... View more
03-19-2021
01:31 PM
However, so far, I can't derive anything meaningful for building the dashboards. I would like to set Splunk to monitor the host operating systems logs files and/or performance data on macOS. I get data in from sources including '/var/log' and '/Library/Logs' but don't see anything meaningful from the data with certain field values filtered. I would also like to monitor the performance data but not sure where they locate at or how to filter the values. Any help would be appreciated! Thanks! System Log Folder: /var/log System Log: /var/log/system.log Mac Analytics Data: /var/log/DiagnosticMessages System Application Logs: /Library/Logs System Reports: /Library/Logs/DiagnosticReports User Application Logs: ~/Library/Logs (in other words, /Users/NAME/Library/Logs) User Reports: ~/Library/Logs/DiagnosticReports (in other words, /Users/NAME/Library/Logs/DiagnosticReports)
... View more
Labels
- Labels:
-
monitoring console
03-18-2021
08:06 AM
Really? But I remember I downloaded Splunk Enterprise for macOS. I downloaded both .tgz and .dmg hoping one of them would start the webserver, but neither of them work. It justs doesn't have the web server and app server like other people do. I have been trying to figure out why.
... View more
03-18-2021
06:53 AM
What are the commands for the firewall permission on MacOS? Thanks
... View more
03-18-2021
04:47 AM
First time installing Splunk. I tried to reinstall the Splunk and web server is still not starting. I also need to change the mgmt port number as the previous one is still using the default port and I have no idea how to disable the previous session. ./splunk start Splunk> Winning the War on Error Checking prerequisites... Checking mgmt port [8111]: open Checking conf files for problems... Done Checking default conf files for edits... Validating installed files against hashes from '/Applications/splunkforwarder/splunkforwarder-8.1.2-545206cc9f70-darwin-64-manifest' All installed files intact. Done All preliminary checks passed. Starting splunk server daemon (splunkd)... Done bin % ./splunk cmd btool web list --debug | grep startwebserver /Applications/splunkforwarder/etc/apps/SplunkUniversalForwarder/default/web.conf startwebserver = 0
... View more
Labels
- Labels:
-
Mac