Activity Feed
- Got Karma for Re: How do I clear out my violations listed in the UI under Manager >> License ?. 12-04-2021 07:49 PM
- Got Karma for Re: How do I tell if a forwarder is down?. 10-18-2021 04:45 PM
- Got Karma for Re: How do i exclude some events from being indexed by Splunk?. 07-29-2021 06:17 PM
- Got Karma for Re: can I have a multiline search box?. 05-09-2021 10:57 PM
- Karma Re: How can I get a complete list of processes used by Splunk for Linux? for hexx. 06-05-2020 12:47 AM
- Karma Re: [SHC] Troubleshooting Configurations under Search Head Clustering for rbal_splunk. 06-05-2020 12:47 AM
- Karma Re: Indexer Clustering Search Factor and Replication Factor not Met for Streaming Buckets for rbal_splunk. 06-05-2020 12:47 AM
- Karma Re: Browser Unsupported on IE after upgrade to 6.2 for jdastmalchi_spl. 06-05-2020 12:47 AM
- Karma Re: Why is the Splunk Web service not running after an upgrade to 6.2? for hexx. 06-05-2020 12:47 AM
- Karma Re: Why does login page show "Your browser could not connect to Splunk.com..." after upgrading server to 6.2 in a closed environment with web.conf configuration? for Ellen. 06-05-2020 12:47 AM
- Karma What are the benefits of the KV store vs a traditional lookup table in Splunk 6.2? for responsys_cm. 06-05-2020 12:47 AM
- Karma Re: What are the benefits of the KV store vs a traditional lookup table in Splunk 6.2? for skylasam_splunk. 06-05-2020 12:47 AM
- Karma Re: What are the benefits of the KV store vs a traditional lookup table in Splunk 6.2? for jlin. 06-05-2020 12:47 AM
- Karma Re: Is it possible to get Splunk version 6.2 as Solaris Package that I can add with pkgadd? for gkanapathy. 06-05-2020 12:47 AM
- Karma Re: how can i see all of the searches that are looking for a specific field? for Flynt. 06-05-2020 12:47 AM
- Karma Re: How to change permissions on Splunk log files? for dshakespeare_sp. 06-05-2020 12:47 AM
- Karma Re: Splunkd SSL and Subject Alternative Names for mgaraventa_splu. 06-05-2020 12:47 AM
- Karma Re: How can I assign the day of the week to my events? for richgalloway. 06-05-2020 12:47 AM
- Karma Re: How can I assign the day of the week to my events? for Flynt. 06-05-2020 12:47 AM
- Karma Re: I changed Splunk from using SSLv3 to TLSv1.2, and the Splunk Java SDK will not connect.. for bosburn_splunk. 06-05-2020 12:47 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
1 | |||
2 | |||
18 | |||
2 | |||
2 | |||
0 | |||
1 | |||
1 | |||
1 | |||
2 |
08-27-2015
10:13 AM
1 Karma
I'd like to be able to assign the day of the week to my events so I can show my users whatever happens on a Monday. Is it possible?
... View more
We are making some changes to our system which requires a field name in the raw event to be changed. We'd like to know the impact to all our users' searches and dashboards that make reference to the field. Is there a way to get an inventory of all the saved searches and dashboards with the field foo in the search string?
... View more
03-13-2015
06:12 PM
3 Karma
I think what is happening here is that chronological order was the last sort order that you selected when you last visited the site.
I just logged in to checked my cases in the support portal and did not have them listed in chronological order, they were sorted by Priority which was how I was looking at my cases a few days ago. I just changed the sort order to be reverse chronological, logged out, and then logged back in -- the cases were displayed in reverse chronological order.
If that is happening for you, let me know and I can follow-up with the right folks
... View more
03-11-2015
10:23 AM
2 Karma
The wget command that I got from the download page is an http connection, not https, and it works as expected.
green@fat ~ $ wget -O splunkforwarder-6.2.2-255606-linux-2.6-x86_64.rpm 'http://www.splunk.com/bin/splunk/DownloadActivityServlet?architecture=x86_64&platform=Linux&version=6.2.2&product=universalforwarder&filename=splunkforwarder-6.2.2-255606-linux-2.6-x86_64.rpm&wget=true'
--2015-03-11 10:17:22-- http://www.splunk.com/bin/splunk/DownloadActivityServlet?architecture=x86_64&platform=Linux&version=6.2.2&product=universalforwarder&filename=splunkforwarder-6.2.2-255606-linux-2.6-x86_64.rpm&wget=true
Resolving www.splunk.com. 54.192.140.45, 54.192.140.114, 54.192.140.61, ...
Connecting to www.splunk.com|54.192.140.45|:80. connected.
HTTP request sent, awaiting response... 302 Moved Temporarily
Location: http://download.splunk.com/products/splunk/releases/6.2.2/universalforwarder/linux/splunkforwarder-6.2.2-255606-linux-2.6-x86_64.rpm [following]
--2015-03-11 10:17:23-- http://download.splunk.com/products/splunk/releases/6.2.2/universalforwarder/linux/splunkforwarder-6.2.2-255606-linux-2.6-x86_64.rpm
Resolving download.splunk.com... 205.251.215.40, 205.251.215.22, 205.251.215.97, ...
Connecting to download.splunk.com|205.251.215.40|:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 13912657 (13M) [application/x-rpm]
Saving to: `splunkforwarder-6.2.2-255606-linux-2.6-x86_64.rpm'
100%[=====================================================================================================================================>] 13,912,657 8.23M/s in 1.6s
2015-03-11 10:17:25 (8.23 MB/s) - `splunkforwarder-6.2.2-255606-linux-2.6-x86_64.rpm' saved [13912657/13912657]`
If you are concerned about the validity of the package you can also wget the md5 or sha512 has by appending the appropriate extension to the end of the file name
... View more
10-30-2014
01:01 PM
18 Karma
I upgraded Splunk Enterprise on Win 2012 from 6.1.4 to 6.2 today, and I am noticing strange behavior from the Splunk Web service:
The Splunk Web service seems to no longer automatically start after the upgrade.
If I go to the Services Manager and attempt to start it manually I get the following:
Error 1053: The service did not respond to the start or control request in a timely fashion
What's odd is the login page is still available via the web interface and logging is still occurring like it should.
Is my upgrade broken?
... View more
Labels
- Labels:
-
upgrade
04-30-2014
10:10 AM
3 Karma
piebob is right, if the system does not recognize your number it will prompt you to enter it. This number should match the number associated with your support profile. You can check this number in the Support Portal under the My Profile section
... View more
10-04-2013
03:50 PM
enable_insecure_login is a setting that was added to allow a dashboard to be rendered in something other than Splunk. Are you doing that in your enviormnent? If not you probably want to disable the setting since it allows credentials to be passed in the clear (hence calling it insecure login). With that said I do not believe that setting is related to your setting. What version of Splunk are you running? Do you have update checking turned on? If you inspect the page in Firebug (or something similar) to do you see an insecure elements in the HTML?
... View more
10-04-2013
03:44 PM
1 Karma
What is the result when you look at the same view on your license master? Is your license master running 6 as well?
... View more
10-04-2013
03:40 PM
1 Karma
Check out this Answers topic: Output syslog to external
Here is the relevant section of the documentation: Forward data to third party systems -- Syslog data
... View more
10-04-2013
03:31 PM
2 Karma
Our testing shows that the new S.o.S is fully functioning in Splunk 6. Sideview will update their compatability table after they have had time to run through their full test suite on Splunk 6.
... View more
05-12-2013
06:30 PM
2 Karma
check out http://wiki.splunk.com/Deploy:Migrating_a_Splunk_Install
... View more
04-24-2013
09:00 AM
If the forwarder was configured to index /var/log/messages/ then it probably just indexed the archived log files.
... View more
10-31-2012
02:11 PM
2 Karma
If I upgrade my Universal Forwarder to 5.0 will it remember where it left off in its files or will it reread from the start of the file?
I'd like to avoid duplicate events after the upgrade
... View more
10-31-2012
09:38 AM
Yes if you delete Splunk while the process is still running the port will continue to be bound.
... View more
10-30-2012
02:33 PM
Can you share some details on the install? What platform are you on (linux, windows, etc.)? What is the method of removal that you used? What was the method of installation of the old version as well as 5.0?
... View more
05-23-2012
11:16 AM
7 Karma
If you are breaking events based on timestamps, that extraction should still work as the format of the timestamp will not change and that is what the linebreaking processor is interested in. What that timestamp actually means in real terms is not a consideration when identifying where to break events.
Any events containing the timestamp with a leap second will be indexed as 23:59:59, and will be searchable.
... View more
QualysGuard is saying that Splunk is vulnerable to cross-site scripting attacks. Can someone confirm if this a valid threat or just a false-positive?
... View more
09-15-2011
02:18 PM
Unixware is not a supported operating system and we do not provide binaries for this platform
... View more
08-22-2011
12:35 PM
Lowell is right, limiting the thruput is not solving the problem and will just cause your forwarders to fall over when their queues fill up. Filtering garbage events and setting alerts for when thruput spikes dangerously is how you should be addressing the problem.
By delaying the amount of data a forwarder can send you are just slowing down the flow of data. The events from the spike will still need to be sent (its just going to take longer for them to get there).
... View more
05-12-2011
04:40 PM
Since Splunk has a webserver how can I have it serve alternate HTML pages? I'd like to provide some simple instructions (and a few other things) to my users and don't really feel like standing up another webserver since I am already running one with Splunk. What directory do I drop files into to have Splunk serve them?
... View more
- Tags:
- splunkweb
05-06-2011
10:26 AM
1 Karma
Can I have a universal forwarder collect data from other universal forwarders and then send that off to the indexer?
... View more
03-28-2011
10:44 PM
enabling the app does not make an instance a universal forwarder. You must install the new universal binaries
... View more
03-22-2011
09:12 PM
1 Karma
If I start off using the tgz installer can I subsequently start using a package installer (rpm or deb)? Is it as simple as pointing the installer at my previous installation?
... View more
03-18-2011
10:57 PM
1 Karma
I've got 2 search heads and 4 indexers. What is the recommended way of upgrading the different components? Should I upgrade the search heads first, then indexers, then forwarders last? Can I live a hybrid state (some 4.1 indexers and some 4.2 indexers)?
... View more
- Tags:
- upgrade
Labels
- Labels:
-
indexer
-
search head
-
upgrade
02-22-2011
06:54 PM
2 Karma
I see timeouts with distributed search and currently have receiveTimeout set to 300. What metric(s) can I use to determine the what should be the correct value this setting in order to avoid timeouts?
... View more