Hi, I can see the below error in the internal logs for a host that is not bringing any logs in Splunk error SSLOptions [17960 TcListener] - inputs. conf/[SSL]: could not read properties; we don’t have ssl options in inputs.conf just wondered if there was any other locations to check on the universal forwarder as it works fine for other servers.
... View more
Hi, just wondered if oracle cloud had tagging to onboard data like AWS does for Splunk like this: splunk add monitor /var/log/secure thanks
... View more
Hi, we have a two site 6 indexer cluster 3 per site and we are upgrading the CPU and each site will be offline for 3 hours per site, do I need to do anything on Splunk or do I need to run ./Splunk offline on 3 indexers at a time before they are shut down? Thanks
... View more
Hi, On certain events the indexed time is 24h after the event _time across all indexes on Splunk cloud, just wondered if anyone has seen this before it doesn’t look to matter on the source type that is used. thanks,
... View more
Hi, I have two servers with identical server classes and apps one has onboard /var/log/secure and one has not, the one that has not has that message about the offset but the one which has doesn't have the offset message.
... View more
Hi,
I am onboarding the /var/log/secure path and i am getting the bellow about offset
INFO WatchedFile
/path/to/file.log
Will begin reading at offset=253 for file
Just wondered what I could do to resolve this?
Thanks,
Joe
... View more
Hi, I am trying to use btool to find an index that is used in an inputs.conf: ./splunk btool inputs list --debug | grep "indexname" However I get nothing back, am I doing something wrong? Thanks, Joe
... View more
Hi,
We have integration with ServiceNow however we have an alert in a custom App to create a ticket to service now however the Problem_URL is wrong and is pointing to the search app instead of the custom app. I have checked the saved search in _internal logs and it is correct.
Any help would be greatly appreciated.
Thanks
... View more
hi, Spunk universal forwarder version 9..0.3 running at 100% cpu on Linux even after a restart is their a known issue/workaround for this? thanks, joe
... View more
Hi,
For field extractions in a clustered environment do you have to use the props.conf method or can you use the field extractor GUI on the search head?
Thanks,
Joe
... View more
Hi,
I have the bellow event:
{"log":"2023-02-16t14:14:25.827471424z stderr F I0216 14:14:25.827359 1 connection.go:153]
connecting to UNIX:///csi/csi.sock"
I need to remove 2023-02-16t14:14:25.827471424z stderr F I0216 14:14:25.827359 and have tried rex but unable to do so, just wondered if someone could help me?
Thanks,
Joe
... View more
Hi,
on Splunk cloud can you create a blank Splunk app for storing dashboards,alerts and reports or does it need reviewing by Splunk?
thanks
... View more
Hi,
on our Splunk instance I have set a report using a time chart with a span of 1h and time frame of a day and the report is scheduled to run every hour however each time the report runs it shows different results. Just wondered if anyone has seen this before?
thanks,
joe
... View more
Hi, just wondering for the Microsoft Cloud Services from the documentation it says it is only required on the search head cluster however it does say optional on the heavy forwarder. My question is usually I setup the inputs on the deployment server however as this is cloud data should the inputs.conf be on the heavy forwarder or the search head? Thanks, Joe
... View more