Activity Feed
- Karma Why does Splunk not recognize standard fields in my Apache data forwarded by syslog? for stefanlasiewski. 06-05-2020 12:47 AM
- Karma Re: Why does Splunk not recognize standard fields in my Apache data forwarded by syslog? for neelamssantosh. 06-05-2020 12:47 AM
- Karma How to configure inputs.conf on a Universal Forwarder to only read the current day's file that contains the date? for lmtaylor. 06-05-2020 12:47 AM
- Karma Re: How to configure inputs.conf on a Universal Forwarder to only read the current day's file that contains the date? for somesoni2. 06-05-2020 12:47 AM
- Karma savedsearches.conf from git: Why are scheduled searches being skipped? for dcparker. 06-05-2020 12:47 AM
- Karma Re: Dashboard Help for wwhitener. 06-05-2020 12:46 AM
- Karma Re: Free License Reset for ChrisG. 06-05-2020 12:46 AM
- Karma Use WGET to download Splunk for rsennett_splunk. 06-05-2020 12:46 AM
- Karma Re: Use WGET to download Splunk for rsennett_splunk. 06-05-2020 12:46 AM
- Karma Re: Use WGET to download Splunk for jreuter_splunk. 06-05-2020 12:46 AM
- Karma Re: Cannot install more than one Splunk Instance on Mac OS using .dmg for dart. 06-05-2020 12:46 AM
- Karma Re: Cannot install more than one Splunk Instance on Mac OS using .dmg for Mick. 06-05-2020 12:46 AM
- Karma Re: Re-Index _internal for rsia23. 06-05-2020 12:46 AM
- Karma License Violation Prediction for kristian_kolb. 06-05-2020 12:46 AM
- Karma Re: clone saved search, 400 times for RicoSuave. 06-05-2020 12:46 AM
- Karma Re: Error: Unable to stop splunk helpers. for Wiggy. 06-05-2020 12:46 AM
- Karma Re: New user to Splunk for MuS. 06-05-2020 12:46 AM
- Karma Re: New user to Splunk for ChrisG. 06-05-2020 12:46 AM
- Got Karma for Re: See count of license violations in last 30 days?. 06-05-2020 12:46 AM
- Got Karma for Re: PDF server: status page timed out. 06-05-2020 12:46 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
1 | |||
2 | |||
47 |
03-28-2014
01:08 PM
Hello,
It is true it can be more complex to set up the IMAP app with Google.
However, you should try first by updating the the imap.conf files (usually under /splunk/etc/apps/imap/local) and adding your Google Account parameters.
For user name and get from your Google account the parameter of your server.
if this does not work.
Did you get a chance to look at this question, already?
... View more
03-27-2014
04:10 PM
2 Karma
Hello,
Yes, it is working.
The IMAP app can be used with Splunk Free license.
We have reference Free vs Enterprise license at Splunk Docs link
And for the IMAP app
When you edit, the imap.conf file in your system, you just need to enter the credential for your mail server.
... View more
12-07-2012
02:25 AM
1 Karma
It is available.
It has been posted on Dec 5th 2012 at here on SplunkBase.
You should be able to download it now.
... View more
12-05-2012
09:32 AM
1 Karma
Hello,
Every time, I install a a second instance of Splunk (same machine, just in a different directory), using the .dmg installer, my original instance gets corrupted and will not work. Multiple directories disappear and of course, I can't execute any of the commands.
My use case is to have two instance for testing purposes.
Thanks
... View more
06-25-2012
11:09 AM
2 Karma
Hello,
Ideally, you would like the new user to be able to access your Splunk instance and, they would be able to view the dashboard you have created and the content from your instance. You would be able to control the data they have access to by updating their role/profile.
If your users need only to review the results of the dashboard; the best way would be to send the dashboard by email to them. They would use their Splunk instance for other work and review your Dashboard results, on the schedule you decide.
You can find the details here:
http://docs.splunk.com/Documentation/Splunk/4.3.2/User/ScheduleDeliveryofDashboardPrintoutsviaEmail
Another option, if you would like to share the format of you dashboard (without the data), one of the possibility would be to copy the XML of your dashboard. Once the new instance is deployed, you will paste the XML in the Dashboard editor.
There are some reference to in our Docs about using XML to created simple and advanced dashboards
http://docs.splunk.com/Documentation/Splunk/4.3.2/Developer/AdvancedIntro#Simplified_XML_and_Splunk.27s_Dashboard_Editor
Finally, you can integrated your dashboard into a Splunk App.
It might be too much effort for sharing a simple dashboard but depending on how many users you are planning to deploy, you might reconsider that.
I am sharing the link to our Documentation, in case you would need some reference about it:
http://docs.splunk.com/Documentation/Splunk/5.0/AdvancedDev/AppIntro
Thank you,
Lionel
... View more
05-09-2012
06:13 PM
10 Karma
Hello,
Another option you may want to try is to do the following:
Increase the pdf_echo timeout here:
$SPLUNK_HOME/lib/python2.7/site-packages/splunk/appserver/mrsparkle/controllers/debug.py
line 438: timeout = 200
Let us know how it works for you
Thanks for using Splunk Answers
... View more
01-26-2012
05:03 PM
Hello,
You should be able to add a new field in your Search and use the avg_trans (numeric) function.
In our example, we have a chart with two calculations on dynamic and one static (e.g. the avg_trans (numeric)) and the search looks something like that:
| eval bytes = bytes / 50 | eval avg_trans = 95
As we are using Real Time Search, it does not displays it at Bar Chart but you should be able to change the format of your graph.
Thank you
Lionel
... View more
12-28-2011
02:22 PM
Hello,
Did you try to update the Splunk Web values of the Splunk Server Name?
You can do that through Splunk Web (Click on Manager, General settings). And I have attached the link to the documentation explaining the different parameters you can use for your reference.
Please check for following page:
http://docs.splunk.com/Documentation/Splunk/latest/Admin/Changedefaultvalues#Changing_the_admin_default_password
This part might be helpful:
Change the default Splunk server name
The Splunk server name setting controls both the name displayed within Splunk Web and the name sent to other Splunk Servers in a distributed setting. The default name is taken from either the DNS or IP address of the Splunk Server host.
via Splunk Web
Log into Splunk Web as the admin user.
Click Manager in the top-right of the interface.
Click the System settings link in the System section of the screen.
Click General settings.
Change the value for Splunk server name and click Save.
Thank you,
Lionel
... View more
12-12-2011
06:01 PM
Hello,
To address this problem, I used a different approach and I am sharing it with you as FYI.
First of all, I downloaded the following App http://splunk-base.splunk.com/apps/22296/real-time-license-usage
called Real Time License Usage and added it as my default dashboard.
So, when I logg in, I see the dial and the information about my license usage.
I know it is not a direct answer to your question and it is just a workaround.
Thank you
Lionel
... View more
Hello,
In addition, I wanted to let you know that there is on SplunkBase a couple of apps that could help you on this matter.
The first App is called "Splunk License Usage" (http://splunk-base.splunk.com/apps/22382/splunk-license-usage) will show you through dashboards your license usage.
The second one is called "Real Time License Usage" (http://splunk-base.splunk.com/apps/22296/real-time-license-usage) will show you, you daily license usage and assist you in monitoring, pro-actively your license usage.
Both of them can be installed on top of 4.2.x, quite easily.
Thank you,
Lionel
... View more
01-26-2011
09:04 PM
2 Karma
Hello,
At the moment, there is no official language coverage when you call in Splunk Support.
In other words, we do not offer, today the ability to route your call to Engineers speaking other languages than English.
That said, we have on board, Engineers who speak other languages than English. We currently have in the team the ability to converse with you in Japanese, Chinese, French, Spanish and Italian. The way to talk to them is when you are calling us, to see whether somebody with additional language knowledge would be available. We will try to accomodate, if possible, but it is not something we are offering at the moment.
We are currently looking into it and evaluating such options for the end of the 2011.
Thank you,
Lionel
... View more
07-21-2010
05:13 PM
2 Karma
Also, you can find on SplunkBase the Splunk License Usage Apps.
In addition to the daily license usage, this Splunk Apps provides a dashboard of your Splunk license usage total over the past 24 hours as well as usage by host, source, and sourcetype. It contains timecharts to help you understand usage over time and see usage spikes as well as pie charts to help you to figure out which log files, sourcetypes, and hosts Splunk is indexing the most data from.
... View more
The reason is because, the Global Summary Index calculate by default the event which are stored in the "main" index.
In the example above, the more recent events were coming from another index (mail in the particular example) and it was not set up correctly under Roles.
To change that:
Login to Splunk
Click on Manager hyperlink (Top right corner)
Click on Access Control (right column)
Click on Roles
Click on Admin (or the relevant user)
Scroll down to the Default index section and make sure, all the indexes you are tracking are under the "selected indexes" column
Uploaded with plasq's Skitch!
... View more
I am logged as Admin in my system and I noticed that the "Global Summary dashboard" does take into consideration all the events in my system.
Why not all the events in my system taking into account in the "Global Summary dashboard" as illustrated below?
Uploaded with plasq's Skitch!
... View more
- Tags:
- configuration
- roles
06-25-2010
12:56 AM
1 Karma
It seems that you have locked your system (we are still indexing data but it is not possible for you to search), in this case you will need to contact Splunk support.
The Support Engineer needs to assist you to re-set your Production license key. In case you are experiencing this problem during an Evaluation of the product (Eval License Key) you can also contact your Sales Account Manager.
... View more
06-25-2010
12:28 AM
2 Karma
It is currently not possible to do that.
For PCI Suite, all the Apps need to appear at the Global level and changing this will negatively affect the PCIComplianceSuite (which is acting as Master Apps).
You could set up two different instances (if you are OK with splitting your data) or two different Search Heads (if you want to keep your data centralized) , one for all logs and one for PCI logs.
... View more
06-11-2010
02:54 PM
1 Karma
There no specific permissions you need to set, but you need to make sure, the user Splunk is installed to run as a member of Administrative group.
If you install Splunk to run as Local System user and Splunk can start and have permission to collect locally, but not on remote machines.
Probably, in some situation, Windows administrator may have set some global settings that don't allow services to run as Local System user.
... View more
05-19-2010
06:54 PM
6 Karma
Splunk delivers Major (X.x.x), minor (x.X.x) and maintenance (x.x.X) releases on a different schedule which can fluctuate depending on the circumstances (product issues) and the feature roadmap.
There is no hard set schedule, however we are trying to maintain the following frequency for our release cycle:
- The Major releases are scheduled on a 12-18 months timeframe.
- The Minor releases are scheduled every 6-8 months.
- The Maintenance releases are usually available on a 6-8 weeks timeframe.
The Maintenance releases are available to provide bug fixes and we do not have any schedule for Patches or Hotfix. In case, we would have to deliver a patch, we will make sure to notify our Users accordingly.
... View more
04-23-2010
09:39 PM
Unfortunately, it is not possible to recover your password.
For security concerns, we are only offering to reset your password (as explained in the postings above).
Once your password has been reset, you can change to the password you like or the one respecting you IT password policy.
... View more
To reset the admin password you will need to have access to the file system:
- move the $SPLUNK_HOME/etc/passwd file to passwd.bak
- restart splunk. After the restart you should be able to login using the default login (admin/changeme).
If you created other user accounts, copy those entries from the backup file into the new passwd file and restart splunk.
It is already answered here:
... View more
03-23-2010
06:10 PM
47 Karma
I just realized that I lost the Admin password and I need a way to access the system, with my Admin credentials.
... View more
Labels
- Labels:
-
login
03-19-2010
04:38 PM
14 Karma
The default credentials are:
Login: admin
password: changeme
... View more