Activity Feed
- Got Karma for Re: is there any limit on length of one event in Splunk ?. 09-21-2020 11:17 PM
- Karma Remove Chart in PDF report in Splunk 5 for asarolkar. 06-05-2020 12:46 AM
- Karma Re: Using Deployment Monitor app to monitor a cluster for araitz. 06-05-2020 12:46 AM
- Karma is_pid_valid for thiru25. 06-05-2020 12:46 AM
- Karma Splunk PDF server for bondu. 06-05-2020 12:46 AM
- Karma Splunk V5 - PDF generation of Dashboards for ppurokit. 06-05-2020 12:46 AM
- Karma Removing charts from scheduled PDF reports? for cruzalan90. 06-05-2020 12:46 AM
- Karma Re: How does splunk licensing work? for sdaniels. 06-05-2020 12:46 AM
- Karma Customise E-mail Alerts PDF Report for Parameshwara. 06-05-2020 12:46 AM
- Karma Re: What are the best practices for installing SoS on cluster? for hexx. 06-05-2020 12:46 AM
- Karma Re: list of hosts for a given time range for _d_. 06-05-2020 12:46 AM
- Karma Re: How to stop a cluster? for gfuente. 06-05-2020 12:46 AM
- Karma Re: How to stop a cluster? for ofrachon. 06-05-2020 12:46 AM
- Got Karma for Re: how to use downloaded apps in splunk. 06-05-2020 12:46 AM
- Got Karma for Re: active directory - how to map user to role ?. 06-05-2020 12:46 AM
- Got Karma for Using Deployment Monitor app to monitor a cluster. 06-05-2020 12:46 AM
- Got Karma for Using Deployment Monitor app to monitor a cluster. 06-05-2020 12:46 AM
- Got Karma for Cluster -> master node and peer node on same machine. 06-05-2020 12:46 AM
- Got Karma for Re: App for Linux on Windows Indexer. 06-05-2020 12:46 AM
- Got Karma for Re: timechart X axis. 06-05-2020 12:46 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
3 | |||
0 | |||
2 | |||
4 | |||
1 | |||
0 |
10-14-2013
04:30 AM
3 Karma
Got this message after upgrading Deployment Server from 5.0.1 to 6.0. Any ideas on what this might be?
... View more
- Tags:
- 6.0
10-03-2013
12:36 AM
I would try to forward the data to the main index to double check the communication between the forwarder and the peers.
I would also go to the UI of every peer to Manager->Indexes and take a look if the index is visible there, enabled, and the configuration of it works fine.
You might use this:
| eventcount summarize=false index=* |
dedup index | fields index
to see if you index is seen by the search head.
... View more
09-13-2013
04:58 AM
1 Karma
The *nix app is designed to work on both Windows and Linux indexers. However it needs to communicate with *nix TA (Technology AddOn) which needs to be installed on the Linux machine you want to collect the data from.
If the UDP Syslog data you want to collect is not specific for *nix app, but is your own -> you don't need to have the *nix app.
... View more
09-09-2013
03:59 AM
The key/value pairs haven't been extracted because Splunk extracts automatically only key/value pairs in form: key=value.
... View more
07-30-2013
01:34 AM
Finally I asked this question during a Splunk Advanced Administration Course. I got the answer that the DM should be installed on the search head. However, in my case the License Manager is not a part of a cluster so to gain the licensing info, I had to add it as a peer to another search head to be queried.
... View more
07-24-2013
05:37 AM
Do you know to which index this sourcetype belongs? Do you have rights to view the events of this index? What role are you using?
... View more
07-23-2013
02:54 AM
4 hosts, 2 clusters on 4 hosts, each cluster on 2 hosts. Each cluster: first host - cluster master + peer, second host - peer + search head.
The forwarders switch the indexers every 60 seconds.
My rep factor = 2, search factor = 2.
I do not need to put all the hosts at once down, I can do that sequentially. I can easily put down the hosts with peer+search_head down, but I do not know how to put down the host with the cluster master so the cluster starts working properly after starting cluster master again.
... View more
07-23-2013
02:34 AM
Yes, the restart is described there, but unfortunately my case is not a restart.
I need to stop the entire cluster (4 instances on 2 hosts), then the hosts are patched and restarted, and after that I need to start the whole cluster again. The patching might take few hours.
... View more
07-23-2013
02:34 AM
Yes, the restart is described there, but unfortunately my case is not a restart.
I need to stop the entire cluster (4 instances on 2 hosts), then the hosts are patched and restarted, and after that I need to start the whole cluster again. The patching might take few hours.
... View more
07-23-2013
02:23 AM
I'm having 2 clusters in my Splunk environment located on 4 hosts.
Due to some patching the hosts need to be restarted and I need to make sure splunk clusters go down safely and after the restart they start properly.
How do I need to do that?
... View more
- Tags:
- cluster
07-02-2013
01:10 AM
If I understand properly, the excel file is your outcome, and what form has the input?
To find first/last occurrence of something I would use streamstats with first()/last() function.
... View more
07-02-2013
12:21 AM
Could you provide some more data? Maybe some example log data to work on?
... View more
06-20-2013
07:01 AM
Are the fields also unavailable under the "View all X fields" link?
... View more
06-19-2013
01:12 AM
From the docs 🙂
http://docs.splunk.com/Documentation/Splunk/latest/Viz/Aboutthismanual
... View more
06-18-2013
06:01 AM
2 Karma
Hi,
If your having it displayed on a dashboard you should use this:
<option name="charting.scaleX">1</option>
<option name="charting.axisLabelsX.majorUnit"> P0Y0M0DT0H30M0S</option>
Hope this helps 🙂
... View more
06-14-2013
02:33 AM
Thanks a lot for the detailes!
... View more
06-06-2013
02:21 AM
This may be helpuf:
http://splunk-base.splunk.com/answers/6358/can-i-change-the-splunk-login-page
On my login page these kind of messages never appear since I bloked the conectivity to splunk.
... View more
06-05-2013
12:28 AM
I think you should be looking at the config files at etc/apps/SplunkUniversalForwarder/local folder. If you have an universal forwarder installed, thats where you should put your config. In the inputs.conf you tell the forwarder which files to monitor. In the outputs.conf you should configure where the data should be sent (your destination (indexer)). Also you should also enable receiving the data on the indexer side (add the [splunktcp://:9997] to the $SPLUNK_HOME/etc/system/local/input.conf). You should also create an index for the data.
... View more
06-03-2013
03:45 AM
Could you paste maybe some extracts from config files (inputs/output.conf?) and tell more about your architecture? Is it only forwarder-indexer or do you have a deployment server installed, too?
My good way to test the installation is to configure passing forwarders own splunkd.log to the indexer - if I see the data than I know that the basic functionality works fine.
If you would like to troubleshoot you should also take a look at the splunkd.log in your var/log/splunk directory.
... View more
05-10-2013
01:20 AM
2 Karma
As written above - are there any good practices for installing Deployment Monitor on a cluster? Is it also pushed from the master to the nodes or installed on search head?
... View more
05-10-2013
01:10 AM
1 Karma
Hi Konrad!
Pozdrowienia z Polski 🙂
To map the groups to roles go to:
Manager->Access Controls->Authentication method->Configure Splunk to use LDAP and map groups->In the Actions section of your LDAP strategy you'll see "Map groups".
Select the right group and the role you want to match with it.
Hope it helps 🙂
asia
... View more
03-28-2013
07:24 AM
4 Karma
As written above - I just set up a cluster (Master, 2 Indexers + SearchHead). Are there some good practices for installing SoS on cluster? Is it also pushed from teh master to the nodes or installed on search head as in distributed deployment?
... View more
03-25-2013
03:44 AM
take a look at:
http://docs.splunk.com/Documentation/Splunk/5.0.2/Data/WhatSplunkcanmonitor
http://docs.splunk.com/Documentation/Splunk/5.0.2/Data/Setupcustominputs
http://docs.splunk.com/Documentation/Splunk/5.0.2/Tutorial/Aboutgettingdatain
... View more
03-20-2013
05:37 AM
Hi,
I would be great if you could give some more details.
To get data from database you would probably need splunk DB Connect app. What info do you need from websites? execl file can also be an input for splunk just like any other log file (for that you need splunk forwarder).
After you will have all the data you need I would recommend to make a dashboard and schedule generating it as a pdf to get reports.
More details would be nice 🙂
... View more