Activity Feed
- Posted Re: Splunk searches delayed on Monitoring Splunk. 02-25-2025 01:25 AM
- Karma Re: Splunk searches delayed for richgalloway. 02-25-2025 01:22 AM
- Posted Splunk searches delayed on Monitoring Splunk. 02-24-2025 11:26 AM
- Posted Re: Enable SSL: Search Head Cluster on Splunk Enterprise Security. 12-23-2024 08:24 AM
- Posted Enable SSL: Search Head Cluster on Splunk Enterprise Security. 12-22-2024 04:45 PM
- Karma Re: DB Connect: Heavy Forwarder Issue for PickleRick. 12-09-2024 06:56 AM
- Posted DB Connect: Heavy Forwarder Issue on Deployment Architecture. 12-09-2024 04:14 AM
- Posted Deploy CIM Add-On On Search Head Cluster on All Apps and Add-ons. 11-26-2024 07:18 AM
- Karma Re: Deploy Windows-TA with Clustered Environment for PickleRick. 11-25-2024 03:08 PM
- Posted Re: Deploy Windows-TA with Clustered Environment on Deployment Architecture. 11-25-2024 02:07 PM
- Karma Re: Deploy Windows-TA with Clustered Environment for PickleRick. 11-25-2024 01:59 PM
- Posted Re: Deploy Windows-TA with Clustered Environment on Deployment Architecture. 11-25-2024 09:36 AM
- Karma Re: Deploy Windows-TA with Clustered Environment for PaulPanther. 11-25-2024 09:27 AM
- Posted Deploy Windows-TA with Clustered Environment on Deployment Architecture. 11-25-2024 07:02 AM
- Karma Re: Ask for the recommended Apps should enhance the Security Posture for meetmshah. 11-25-2024 04:05 AM
- Posted Re: How To Create HEC Http_Input in Indexer Cluster Envirmment on Getting Data In. 11-23-2024 09:39 AM
- Karma Re: How To Create HEC Http_Input in Indexer Cluster Envirmment for marnall. 11-23-2024 09:38 AM
- Posted Re: How To Create HEC Http_Input in Indexer Cluster Envirmment on Getting Data In. 11-23-2024 09:37 AM
- Karma Re: How To Create HEC Http_Input in Indexer Cluster Envirmment for PickleRick. 11-23-2024 09:35 AM
- Posted How To Create HEC Http_Input in Indexer Cluster Envirmment on Getting Data In. 11-23-2024 04:22 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 |
02-25-2025
01:25 AM
Thanks for your help, really appreciated! As per the below Screenshot: Convert real-time searches into scheduled searches. is real time = Ad-hoc? Could you please assist in differentiate the difference between the (Historical - Realtime - Summarization - Ad-hoc) Searches?
... View more
02-24-2025
11:26 AM
Hello, I faced the below ERROR: The percentage of non high priority searches delayed (27%) over the last 24 hours is very high and exceeded the red thresholds (20%) on this Splunk instance. Total Searches that were part of this percentage=18. Total delayed Searches=5 Search for the result:
... View more
Labels
- Labels:
-
resource usage
-
search head
12-22-2024
04:45 PM
Hello, While trying to deploy the ES using the Deployer GUI, I want to Enable SSL However I faced the below:
... View more
Labels
12-09-2024
04:14 AM
Hello,
I have a Heavy Forwarder, and it was configured just to forward not index:
[indexAndForward]
index = false
I tried to install the DB Connect App on that HF but we faced the below ERROR:
Any Ideas?
... View more
Labels
- Labels:
-
heavy forwarder
11-26-2024
07:18 AM
HI Everyone, Hope you all are doing well. I am trying to deploy the CIM on Search Head Cluster Environment, and I have some questions: 1- I found under /default two files (inputs.conf & indexes.conf) that seems to me they are related to indexer cluster not search heads cluster, am I true? 2- what is "cim_modactions index definition is used with the common action model alerts and auditing", i didnt know the actual meaning? Splunk Common Information Model (CIM)
... View more
Labels
- Labels:
-
configuration
-
installation
11-25-2024
02:07 PM
Yes, this is the confusing point. Did you mean if my search is: index = main eventtype=authentication This search will replicate the knowledge bundle which contains the relative Knowledge Object to the search itself not all the Knowledge Object which exists on the search head? Knowledge bundle replication overview - Splunk Documentation "The process of knowledge bundle replication causes peers, by default, to receive nearly the entire contents of the search head's apps." Any explanation will be greatly appreciated!
... View more
11-25-2024
09:36 AM
Thanks for your help! I am still confusing how indexer cluster should be managed, if i want to create any KOs at the search head side, should i push these KOs to the indexers also?
... View more
11-25-2024
07:02 AM
Hello Splunker, I hope you all are doing well. I have tried to deploy the Windows-TA Add-On over my environment [Search Head Cluster + Deployer] [3 Indexer Peer + Indexer Cluster Master] [Deployment Server + Universal Forwarder]. I have used the Deployment server to push the inputs.conf to the designated universal forwarder which allocated on the domain controller server and enable the needed. then remove the wmi.conf and inputs.conf from the Windows TA-Add-On, and copy the rest to local folder and used the deployer to push the enhanced Windows TA to the search heads. As per the below screen from the official doc the indexer is conditional: Why should push the Add-on to the indexers even if there are an index time field extraction? As i am know the search head cluster will replicate all the knowledge bundle with the indexers so all the KOs will be replicated to the indexers and no need to push them, am i correct? Splunk Add-on for Microsoft Windows Thanks in advance!!
... View more
11-23-2024
09:39 AM
Kindly, let me know why you need to skip _cluster path?
... View more
11-23-2024
09:37 AM
Yes, I know the WebUI should be disabled for the indexers, but it's test environment so it's enabled.
... View more
11-23-2024
04:22 AM
Hello,
I want to create Input: HEC on the indexers => Indexer Cluster.
Create inputs.conf under /opt/splunk/etc/master-apps/_cluster/http_input/local:
[http]
disabled=0
enableSSL=0
[http://hec-input]
disabled=0
enableSSL=0
#useACK=true
index=HEC
source=HEC_Source
sourcetype=_json
token=2f5c143f-b777-4777-b2cc-ea45a4288677
Push these configuration to the peer-app (Indexers).
But we go to the Data inputs => HTTP Event Collector at indexer Side
we still found it as below:
... View more
Labels
- Labels:
-
HTTP Event Collector
-
inputs.conf
11-13-2024
02:19 PM
Reply: Can we enforce the data to be rolled from the Hot/warm to Cold after one month then from Cold to frozen after one month.
... View more
11-13-2024
02:16 PM
Hello Splunker,
I have two volumes with the following specs:
Hot/Warm Volume: 5.25 TB
Cold Volume: 4.75 TB
================================
[volume:hot]
path = /opt/splunk-hwdata
maxVolumeDataSizeMB = 7602176
[volume:cold]
path = /opt/splunk-Colddata
maxVolumeDataSizeMB = 4980736
==================================
[Win]
repFactor = auto
homePath = volume:hot/$_index_name/db
coldPath = volume:cold/$_index_name/colddb
thawedPath = /opt/splunk-Colddata/$_index_name/thaweddb
homePath.maxDataSizeMB = 7602176
coldPath.maxDataSizeMB = 4980736
maxWarmDBCount = 720
frozenTimePeriodInSecs = 5184000
maxDataSize = auto_high_volume
[FW]
repFactor = auto
homePath = volume:hot/$_index_name/db
coldPath = volume:cold/$_index_name/colddb
thawedPath = /opt/splunk-Colddata/$_index_name/thaweddb
homePath.maxDataSizeMB = 7602176
coldPath.maxDataSizeMB = 4980736
maxWarmDBCount = 720
frozenTimePeriodInSecs = 5184000
maxDataSize = auto_high_volume
====================================
Notice we have re-configured the below:
[diskUsage]
minFreeSpace = 20000
Finally, we have reached the bottom of the question 😀.
I am doubt if this configuration can maintain the below requirements:
The data retention period for the online data is 2 months.
- Hot/Warm – 1 month
- Cold – 1 month
... View more
Labels
- Labels:
-
indexer clustering
11-11-2024
04:54 PM
Hello Esteemed Splunkers, I have a long question, and I wish to have a long and detailed discussion ^-^ First of all: We have a distributed environment: Deployer with 3x search heads. indexer master with 3x indexer. Deployment server with 2x heavy forwarder. and we want to deploy "Splunk_TA_fortinet_fortigate" the below is the content: the question is: should we deploy this app from the deployer to all search heads? should we deploy this app from the Indexer Master to all indexers? should we deploy this app from the deployment server to all heavy forwarders? should we change the name of the default folder to local? In a nutshell, what should we do and the consideration should we look at? Thanks in advance!
... View more
Labels
11-09-2024
05:39 AM
Hello ES Splunker, I want to know if any applications can be installed to enhance the security posture alongside with Enterprise Security. is ITSI App added value for the security posture?
... View more
Labels
10-20-2024
07:25 AM
Thanks! Could you elaborate more on EPS OR GB/Day?
... View more
10-20-2024
06:13 AM
Hello, I am writing to ask from which point regarding the EPS OR Daily ingested GB/day and the number of users simultaneously access the search head. at what point should i consider a cluster search head cluster, as it will be (one-single SH ) OR (three SH + Deployer)? from your technical perspective?
... View more
07-11-2024
09:23 AM
Hello Splunker, Hope you had a great day! as per the below picture : Q1:- I need to understand the exact process of creating the TSIDX file and its content and how actually it speeds the search? Q2:- Why the size of the tsidx file is bigger than the raw data itself 35% /15%? Q3:- what is the difference between tsidx file and datamodel summary? I am expecting a long answer and more details, actually i like details! Thanks in advance!
... View more
Labels
- Labels:
-
alias
-
field extraction
-
summary indexing
07-04-2024
12:42 PM
Hi, I hope all is well. I have struggled with Data Model Concept as I seek to know why and When we use the data model and how it increases the performance? I am fine with it's structured data and has three type of data sets, also I am able to create it as How To. But why use it? When use it? what is the main idea behind it?
... View more
Labels
- Labels:
-
alias
-
data model
-
summary indexing
07-01-2024
06:23 AM
I am trying to test the Index Time field extraction, and want to know how to refine the field extraction using source_key Keyword. Then how can i refine my Field extraction if i cant use the SOURCE_KEY twice?
... View more
06-30-2024
10:23 AM
I Have used the below two events to test the SOURCE_KEY = <132>1 2023-12-24T09:48:05+00:00 DCSECIDKOASV02 ikeyserver 8244 - [meta sequenceId="2850227"] {Warning}, {RADIUS}, {W-006001}, {An invalid RADIUS packet has been received.}, {0x0C744774DF59FC530462C92D2781B102}, {Source Location:10.240.86.6:1812 (Authentication)}, {Client Location:10.240.86.18:42923}, {Reason:The packet is smaller than minimum size allowed for RADIUS}, {Request ID:101}, {Input Details:0x64656661756C742073656E6420737472696E67}, {Request Type:Indeterminate} <132>1 2023-12-24T09:48:05+00:00 DCSECIDKOASV02 ikeyserver 8244 - [meta sequenceId="2850228"] {Warning}, {RADIUS}, {W-006001}, {An invalid RADIUS packet has been received.}, {0xBA42228CB3604ECFDEEBC274D3312187}, {Source Location:10.240.86.6:1812 (Authentication)}, {Client Location:10.240.86.19:18721}, {Reason:The packet is smaller than minimum size allowed for RADIUS}, {Request ID:101}, {Input Details:0x64656661756C742073656E6420737472696E67}, {Request Type:Indeterminate} Using the below Regex: [xmlExtractionIDX] REGEX = .*?"]\s+\{(?<Severity>\w+)\},\s+\{\w+\},\s+\{(?<DeviceID>[^}]*)\},(.*) FORMAT = Severity::$1 DeviceID::$2 Last_Part::$3 WRITE_META = true till that it's working fine then i want to add more precise extraction and want to extarct more info from the Last_Part field using the SOURCE_KEY = [xmlExtractionIDX] REGEX = .*?"]\s+\{(?<Severity>\w+)\},\s+\{\w+\},\s+\{(?<DeviceID>[^}]*)\},(.*) FORMAT = Severity::$1 DeviceID::$2 Last_Part::$3 SOURCE_KEY = MetaData:Last_Part REGEX = Reason:(.*?)\} FORMAT = Reason::$1 WRITE_META = true But it doesn't work now, Is there any advice to do that using SOURCE_KEY
... View more
Labels
- Labels:
-
field extraction
-
metadata
-
regex
06-25-2024
09:13 AM
Hello, I hope all is well. Need your help to monitor the F5 Interface utilization throughput (performance Monitor). Any Idea! @community #performanceMonitor
... View more
Labels
- Labels:
-
Classic dashboard
-
panel