Activity Feed
- Karma Re: Connect Splunk DB Connect to MariaDB with SSL and cert for ShaneNewmanRH. 10-29-2024 06:21 AM
- Got Karma for Re: How to change the width of two dashboard panels in the first row from 50% 50% to 75% 25% in Simple XML for Splunk 6.2?. 02-23-2024 05:07 AM
- Got Karma for Re: Splunk external lookup script within app not running. 02-21-2024 11:38 AM
- Got Karma for Re: apply shcluster-bundle returning insufficient permission to access this resource. 01-11-2023 09:30 AM
- Karma Event_breaker vs Line_breaker ? for daniel333. 10-13-2022 01:49 AM
- Got Karma for Re: How to delete data / index (reset start from scratch). 09-27-2022 01:31 PM
- Posted Re: Why do Custom Alert Actions values of Yes or No in a selection take different values? on Alerting. 10-11-2021 04:58 AM
- Karma Re: Where should I check for python.log error messages about generating pdf of scheduled reports? for ronogle. 09-15-2021 02:32 AM
- Karma Re: How to include an app name as a part of the search query? for martin_mueller. 07-07-2020 01:43 PM
- Karma The add-on for Symantec Endpoint Protection (https://splunkbase.splunk.com/app/2772/) is not extracting the fields by default. version 3.0.0 for dkolekar_splunk. 06-05-2020 12:51 AM
- Karma Re: The add-on for Symantec Endpoint Protection (https://splunkbase.splunk.com/app/2772/) is not extracting the fields by default. version 3.0.0 for dkolekar_splunk. 06-05-2020 12:51 AM
- Karma Fork of Splunk Add-on for Check Point OPSEC LEA for Splunk ES for simonsigre. 06-05-2020 12:50 AM
- Karma Re: Create Oracle Connection: Cannot load connection class because of underlying exception: com.mysql.cj.exceptions.WrongArgumentException: Malformed database URL, failed to parse the main URL sections. for earlhelms. 06-05-2020 12:50 AM
- Karma DBConnect: OSError: [Errno 2] No such file or directory validate java command: /usr/java/latest/bin/java. for Branden. 06-05-2020 12:50 AM
- Karma Re: DBConnect: OSError: [Errno 2] No such file or directory validate java command: /usr/java/latest/bin/java. for teunlaan. 06-05-2020 12:50 AM
- Got Karma for Re: Local processing of forwarded events on heavy forwarder issues. 06-05-2020 12:50 AM
- Karma Re: How do I reload a configuration file that does not require a restart? for yannK. 06-05-2020 12:49 AM
- Karma Create field extractions without the capability admin_all_objects for cesarb. 06-05-2020 12:49 AM
- Karma How to recalculate earliest and latest in view? for schose. 06-05-2020 12:49 AM
- Karma Re: How to recalculate earliest and latest in view? for niketn. 06-05-2020 12:49 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 |
10-11-2021
04:58 AM
Hi, I came accross this old question via google search on alert on splunk-control-group topic. As there is not much information in docs and answers, it might be still relevant. Did you specify action.hipchat.param.color in apps/README/alert_actions.conf.spec file as <boolean>? If so, you can change it to <string> and see, if it makes a difference? Best regards
... View more
05-25-2020
04:06 AM
According to our documentation, AIX is not supported.
Has this changed in Version 8.x ?
Until 7.3.5 the documentation is listing the supported versions. Beginning with 8.0.0 it revers to the Supported Operating Systems, which includes AIX as suppported for Universal Forwarder:
http://docs.splunk.com/Documentation/Splunk/8.0.0/Installation/Systemrequirements#Supported_Operating_Systems
... View more
04-08-2020
11:27 AM
I had the same problem in Splunk 7.3.4.2 and DB-Connect 3.2.0
I tried to made a new Oracle-DB-Connection and got mySQL error message. When I removed mySQL driver from DB-Connect I got the correct error message from Oracle jdbc driver.
As suggested by earlhelms it seems to be a bug in the mySQL jdbc driver, so I updated this driver from version 8.0.11 to 8.0.19 and this seems to solve the issue.
... View more
04-08-2020
11:25 AM
I had the same problem in Splunk 7.3.4.2 and DB-Connect 3.2.0
I tried to made a new Oracle-DB-Connection and got mySQL error message. When I removed mySQL driver from DB-Connect I got the correct error message from Oracle jdbc driver.
As suggested here it seems to be a bug in the mySQL jdbc driver, so I updated this driver from version 8.0.11 to 8.0.19 and this seems to solve the issue.
... View more
03-10-2020
10:46 AM
Yes, the SplunkBase site is showing combatibility to CIM Version 4.x
https://splunkbase.splunk.com/app/1915
... View more
02-24-2020
05:43 AM
I think best idea is to file a case at Splunk support to receive the most current beta version of props/transforms. Or to wait for version 3.0.1 of the Add-On.
Best regards
... View more
12-10-2019
07:04 AM
Hi, I have the same problem with rotated logfiles.
I'm using Universal Forwarder in version 6.4.5 to monitor a log file and it's rotated versions. There was a network outage and the UF was not able to send it's data for some time. In the meanwhile the logs were rotated and zipped. The files it never began to read were read fine after the Network problem was resolved - even the zipped ones. But the file it was reading at the beginning of the outage was only unzipped and then commented with "already read, so skipped".
When I manually unpacked the file and put it in place the UF started reading where it stopped because of the outage. So I think UF is skipping the check of the seekCRC at seekAdress as mentioned here:
https://docs.splunk.com/Documentation/Splunk/6.4.5/Data/HowLogFileRotationIsHandled
Does anyone know, if this is resolved in any Version?
... View more
08-21-2019
02:12 AM
I opened a case and it's confirmed, that the ER was not implemented by now. Our need is now added to ER SPL-175134, but no big hope for having this implemented soon.
... View more
08-19-2019
05:53 AM
Hi, yo you have any information, if this Enhancement Request was implemented?
... View more
01-31-2019
02:23 AM
I had problems using the [default] stanza, too. You can try this:
You can also define global settings outside of any stanza, at the top of the file.
... View more
01-31-2019
02:21 AM
1 Karma
This is not effecting transforms, just line-merging or timestamp recognition etc. (parsing and aggregation Queue)
See: https://wiki.splunk.com/Community:HowIndexingWorks
If you want to "re-parse" Events you can try the setting in inputs.conf like suggested here:
https://answers.splunk.com/answering/275684/view.html
... View more
01-31-2019
01:32 AM
Have you tried setting the _SYSLOG_ROUTING via props/transforms as suggested here:
https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad
Can you please give a config example of your props/transforms which is not working as expected?
... View more
For those who come to this page looking for an answer how to avoid giving a user admin_all_objects capability, if you only want the user to do a "splunk apply shcluster-bundle"...
We opened a case for this (1165853) and there is a solution:
You can build a custom role for this.
Step 1: Define a new capability and assign it to a role - via authorize.conf
[capability::deployer_capability]
[role_deployer]
deployer_capability = enabled
Step 2: Assign the capability to the correct REST endpoint, which is used by this CLI command - via restmap.conf
[apps-deploy:apps-deploy]
capability.post=deployer_capability
This is working pretty fine for us and we can now have a techical user doing a "splunk apply shcluster-bundle" without having a technical user with admin priviliges.
... View more
11-13-2018
09:03 AM
We opened a case for this (1165853) and there is a solution:
You can build a custom role to not need a user to have admin_all_objects capability.
Step 1: Define a new capability and assign it to a role - via authorize.conf
[capability::deployer_capability]
[role_deployer]
deployer_capability = enabled
Step 2: Assign the capability to the correct REST endpoint, which is used by this CLI command - via restmap.conf
[apps-deploy:apps-deploy]
capability.post=deployer_capability
This is working pretty fine for us and we can now have a techical user doing a "splunk apply shcluster-bundle" without having a technical user with admin priviliges.
... View more
11-13-2018
09:03 AM
1 Karma
We opened a case for this (1165853) and there is a solution:
You can build a custom role to not need a user to have admin_all_objects capability.
Step 1: Define a new capability and assign it to a role - via authorize.conf
[capability::deployer_capability]
[role_deployer]
deployer_capability = enabled
Step 2: Assign the capability to the correct REST endpoint, which is used by this CLI command - via restmap.conf
[apps-deploy:apps-deploy]
capability.post=deployer_capability
This is working pretty fine for us and we can now have a techical user doing a "splunk apply shcluster-bundle" without having a technical user with admin priviliges.
... View more
11-13-2018
08:50 AM
We opened a case for this problem (1175734). There is a quite simple workaroud for this (if you know about it):
Just add the following code to etc/system/local/restmap.conf:
[eai:conf-transforms]
capability.write=allow_access_to_all
But the problem is also filed as a bug: SPL-162527
... View more
06-26-2018
04:21 AM
Helped for me - nice solution. Should be accepted answer 😉
Thank you very much.
... View more
03-12-2018
05:46 AM
1 Karma
I think you want to sort the order of the fields in a table based on which savedsearch the events are from. For this you need to search for a specific saved_search. Then you have a lookup with a 1:1 connection between savedsearch and format. If this is true, try the following:
index=summary search_name="your_saved_search"
| table
[ | inputlookup formatting.csv
| search search_name="your_saved_search"
| fields format
| rename format as search ]
Background for this is, that a field named "search" from a subsearch is interpreted as SPL in the base search.
... View more
10-29-2017
01:55 PM
Did you try the TERM() keyword? The magic behind it is described in this session for example: Indexed Tokens and you
I was able to greatly improve searches for single IP addresses with TERM(). It's working even better when the logs you are searching in do not have quotes (") around the value of dest_ip and have field=value in the _raw data. Because you can then do something like TERM(dest_ip=192.168.1.1).
You can even use the inputlookup @masonmorales suggested, when you know how to format the output of a subsearch:
index=network sourcetype=fgt_traffic [|inputlookup match_address
| eval search="TERM(".match_address.") OR "
| stats values(search) as search
| nomv search
| eval search="(".rtrim(search, " OR ").")"]
Edit: Insert " OR " between terms.
... View more
10-25-2017
02:42 AM
Already answered here: https://answers.splunk.com/answering/11189/view.html
If there are multiple timestamps, you can use a custom DATETIME_CONFIG instead of specifying TIME_FORMAT and TIME_PREFIX.
... View more
05-17-2017
01:59 AM
Thanks. Can you keep us informed about the bug status here or should I open a case?
You workaround is a good idea, but it's not working for us. If I switch log level to ERROR, I will not receive correct warnings anymore.
We need the warnings to see, if someone forgets the line-breaking marker "\" if a search or any other value is using multiple lines. In worst case we have a saved search which is missing some lines, because of missing "\", which might result in a security event not recognized...
... View more
05-15-2017
03:16 AM
Is there any news on this?
I have the same errors since updating from 6.4.4 to 6.5.3
... View more
03-23-2017
01:14 AM
Looks like the same Problem here: https://answers.splunk.com/answering/492028/view.html
Splunk states, that the message can be ignored and they are still working on a fix.
A workaround might be to disable Boot-Start of the Forwarder.
... View more
03-23-2017
01:09 AM
Any news here? We have the same error with AIX and Splunk Universal Forwarder 6.4.5
... View more
03-21-2017
09:09 AM
I downvoted this post because it is not respecting the fact, that _TCP_Routing = * is set by Splunk's default on Universal Forwarders as stated already in the question.
... View more