I plan to deploy the Splunk UF across all my Windows client PCs using SCCM. But I'm confused about the index settings. I want to send all the data to a specific index but when the UF installs it just defaults to the main index. Is there a way to specify the index during installation? As I don't want data going to main before I change it.
... View more
So in that section I have Licenses Volume Expiration Status Splunk Enterprise Term License 12,288 MB 2027 FROM_THE_FUTURE Effective daily volume 0 MB auto_generated_pool_enterprise 941 MB / 0 MB
... View more
Hi, Yes it's set to "This server is configured to use licenses from the Enterprise license group". On the same page there's a section "Splunk Enterprise Term License stack" with volume 12,288 MB. The auto-generated_pool_enterprise shows 932 MB / 0 MB.
... View more
I used a ldp.exe (using the same bind DN as Splunk) and it returned the expected results (6 AD groups). Splunk only returns 3. The Group Base DN: "ou=Splunk,ou=Application_Groups,ou=Security Groups,dc=office,dc=local" The Group attribute name: "cn" Static member attribute: "memberof" User base DN: "ou=DomainUsers,dc=office,dc=local"
... View more
I had the free version of Splunk and after a while search was disabled since ingest was over 500MB. So I purchased a 12GB Enterprise license and installed it a few days ago. Now I'm getting warnings "This pool has exceeded its configured poolsize=0 bytes" every day. My daily ingest per day since I installed the license is 1.7GB. I am also still getting a warning "Daily indexing volume limit exceeded. Your Splunk deployment is subject to license enforcement". I thought this would go away once I installed the licence. I am using Splunk Enterprise 10.0.2 on Windows Server 2025. Thank you for your help.
... View more
Hi all, I have setup an LDAP connection to my AD server. But when I click on LDAP Groups, not all groups are displayed (missing 2 out of 5). I have no static group search filter. The group that is missing has 1 user in. This user is in the same User base DN as the LDAP config (which also does not have a User base filter). This is a brand new install. I want to assign that AD group the Admin role in Splunk. I am using Splunk Enterprise 10.0.2 on Windows Server 2025. Thank you for your help.
... View more