I have the same problem - but with fresh installs, when is no passwords set up. We only started having the problem since upgrading to Splunk 8. I was able to workaround it by placing an account/password file manually in the inputs dir. It wasn't a valid hash but it was enough to get the GUI to load and then I could change the password to a correct one. This workaround was straightforward as I already had a working version on splunk 7. However it doesn't work for installing something for the first time on V8 as I don't know what a valid account/password file looks like.
... View more
[eliminate-screenconnect]
REGEX = screenconnect\.techmedia\.com\.au
DEST_KEY = queue
FORMAT = nullQueue A simple REGEX is enough for nullQueue.
... View more
FINAL UPDATE FROM ME - this was caused by Microsoft graphing add-on had some credential errors (copied/deployed form another forwarder by mistake) removing this app and its all working again as expected.
... View more
Hey @mjm295, if @cmerriman's solution worked then please don't forget to accept her answer to award karma points and close the question. 🙂
... View more
AH nailed it
| stats sum(PricePerYr) as "Compute OPEX (US$/yr)", sum(totalPerYr) as "Total OPEX", count as "Instance Count" by Service | eval Avg_total_cost_per_instance=('Total OPEX' / 'Instance Count' )
Simple
... View more
ok did some more reading and stuck with the second option but added
kvmode = none
to my search head props (for this 1 source,, now I am seeing all results, but only 1 set.
i need to understand the indexed extractions better...
... View more