Activity Feed
- Karma Re: Splunkd crash after upgrade to 4.3 for hexx. 06-05-2020 12:46 AM
- Karma Re: Lookups within a search head pool not finding shared storage lookup table for ewoo. 06-05-2020 12:46 AM
- Karma Re: Why isn't my lookup working? for Paolo_Prigione. 06-05-2020 12:46 AM
- Karma Issue with Palo Alto apps for gskorski. 06-05-2020 12:46 AM
- Karma Re: Issue with Palo Alto apps for gskorski. 06-05-2020 12:46 AM
- Karma Re: How do you search results produced from a timechart...by command? for Damien_Dallimor. 06-05-2020 12:46 AM
- Karma Re: Communication failing between forwarder and receiver for kristian_kolb. 06-05-2020 12:46 AM
- Got Karma for Lookups within a search head pool not finding shared storage lookup table. 06-05-2020 12:46 AM
- Got Karma for Why isn't my lookup working?. 06-05-2020 12:46 AM
- Got Karma for Why isn't my lookup working?. 06-05-2020 12:46 AM
- Got Karma for Re: Why isn't my lookup working?. 06-05-2020 12:46 AM
- Got Karma for Allowing a role to write to a non-standard summary index. 06-05-2020 12:46 AM
- Got Karma for Re: Has anyone gotten Splunk for Bluecoat working?. 06-05-2020 12:46 AM
- Got Karma for Re: Has anyone gotten Splunk for Bluecoat working?. 06-05-2020 12:46 AM
- Got Karma for Re: Has anyone gotten Splunk for Bluecoat working?. 06-05-2020 12:46 AM
- Got Karma for Re: why stats last and first are inverted ?. 06-05-2020 12:46 AM
- Got Karma for Re: why stats last and first are inverted ?. 06-05-2020 12:46 AM
- Got Karma for Re: why stats last and first are inverted ?. 06-05-2020 12:46 AM
- Got Karma for Re: why stats last and first are inverted ?. 06-05-2020 12:46 AM
- Got Karma for Re: why stats last and first are inverted ?. 06-05-2020 12:46 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
1 | |||
0 | |||
0 | |||
2 | |||
1 |
07-18-2012
06:43 PM
As with http://splunk-base.splunk.com/answers/11680/sedcmd-not-executing, if there is a heavy forwarder processing the data before the indexer, the SEDCMD and other parsing happens there.
See http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings for more details
... View more
06-27-2012
06:56 PM
1 Karma
I have created a new summary index (let's call it summary_example) so that we can use it in an app as a destination for summary indexing.
I have given the appropriate role read access to the index, but it doesn't show up in the dropdown when enabling summary indexing for a saved search. If I do it using an admin user, it does show up.
This suggests that there is either a permission I can grant to allow write access to the summary index by the role, or a capability that the role should have to allow it to write to all summary indexes (I'd prefer the former for obvious reasons)
... View more
04-02-2012
05:54 PM
We have the exact same problem. Interesting to know if anyone has a solution. sourcetype=pan_log finds lots of logs containing the regex ,TRAFFIC, as per transforms.conf
... View more
03-18-2012
04:16 PM
I was misunderstanding the [splunktcp://ipaddress:port] configuration.
I thought the ipaddress was localhost, but it's actually remoteserver (forwarders that are allowed to connect).
Adding the new forwarders to inputs.conf fixes this issue. Thanks to Kristian for helping me look in the right direction.
... View more
03-15-2012
09:28 PM
My new forwarder appears not to be talking to the configured indexer(s)
[tcpout]
defaultGroup = splunk1_9997_splunk2_9997
disabled = false
indexAndForward = 0
[tcpout:splunk1_9997_splunk2_9997]
autoLB = true
server = splunk1:9997,splunk2:9997
I have another forwarder with an identical outputs.conf and that works fine.
Inputs.conf on the indexers looks like:
[splunktcp://10.1.2.1:9997]
On the forwarder
03-16-2012 14:20:24.902 +1000 INFO TcpOutputProc - Connected to idx=10.1.2.3:9997
03-16-2012 14:20:24.902 +1000 INFO TcpOutputProc - Connection to 10.1.2.3:9997 closed. Connection closed by server.
03-16-2012 14:20:24.903 +1000 WARN TcpOutputProc - Applying quarantine to idx=10.1.2.3:9997 numberOfFailures=2
03-16-2012 14:20:24.903 +1000 INFO TcpOutputProc - Connected to idx=10.1.2.3:9997
03-16-2012 14:20:24.904 +1000 INFO TcpOutputProc - Connection to 10.1.2.3:9997 closed. Connection closed by server.
03-16-2012 14:20:24.904 +1000 WARN TcpOutputProc - Applying quarantine to idx=10.1.2.3:9997 numberOfFailures=3
On the indexer
03-16-2012 14:20:24.903 +1000 INFO TcpInputProc - No matching config for 10.1.2.4
03-16-2012 14:20:24.903 +1000 WARN TcpInputProc - Could not find matching host.
03-16-2012 14:20:24.903 +1000 INFO TcpInputProc - No matching config for 10.1.2.4
03-16-2012 14:20:24.903 +1000 WARN TcpInputProc - Could not find matching host.
03-16-2012 14:20:24.904 +1000 INFO TcpInputProc - No matching config for 10.1.2.4
03-16-2012 14:20:24.904 +1000 WARN TcpInputProc - Could not find matching host.
03-16-2012 14:20:24.904 +1000 INFO TcpInputProc - No matching config for 10.1.2.4
03-16-2012 14:20:24.904 +1000 WARN TcpInputProc - Could not find matching host.
What matching config is it looking for? Connectivity is definitely fine.
Updated Corrected inputs.conf to outputs.conf, added indexer inputs.conf as per Kristian's comment
... View more
03-12-2012
06:57 PM
5 Karma
Note that
earliest
latest
also exist which have the meanings that you seem to be looking for from first and last.
... View more
03-12-2012
05:55 PM
3 Karma
This seems tied to the eventtype=bcoat_request in the BlueCoat - Datacube and BlueCoat - Datacube - Summary Index saved searches.
By editing the saved search and replacing eventtype=bcoat_request in both searches with the expansion from macros.conf, i.e.
sourcetype=bcoat_cacheflow OR (sourcetype=bcoat_proxysg filter_result!="DENIED")
the application works. Editing default/savedsearches.conf directly didn't seem to force this, even with a restart. Adding a local/savedsearches.conf with the correct stanzas (which I achieved through editing the saved search in Manager) does have the desired effect.
local/savedsearches.conf now contains
[BlueCoat - DataCube]
action.email.inline = 1
alert.digest_mode = True
alert.suppress = 0
alert.track = 0
search = sourcetype=bcoat_cacheflow OR (sourcetype=bcoat_proxysg filter_result!="DENIED") | bin _time span=5m | makemv delim=";" allowempty=t category | fillnull src_ip cs_bytes category dest_host rs_bytes sc_bytes sc_status sr_bytes | eval client_bytes=sc_bytes+cs_bytes | eval server_bytes=rs_bytes+sr_bytes | eval savings_bytes=client_bytes-server_bytes | eval savings_bytes=if(server_bytes==0,0,savings_bytes) | eval savings_perc = (1/client_bytes) * savings_bytes * 100 | stats count by host src_ip sourcetype category dest_host server_bytes client_bytes savings_bytes savings_perc _time
[BlueCoat - DataCube - Summary Index]
action.email.inline = 1
alert.digest_mode = True
alert.suppress = 0
alert.track = 0
search = sourcetype=bcoat_cacheflow OR (sourcetype=bcoat_proxysg filter_result!="DENIED") | bin _time span=5m | makemv delim=";" allowempty=t category | fillnull src_ip cs_bytes category dest_host rs_bytes sc_bytes sc_status sr_bytes | eval client_bytes=sc_bytes+cs_bytes | eval server_bytes=rs_bytes+sr_bytes | eval savings_bytes=client_bytes-server_bytes | eval savings_bytes=if(server_bytes==0,0,savings_bytes) | eval savings_perc = (1/client_bytes) * savings_bytes * 100 | sistats count by host src_ip sourcetype category dest_host server_bytes client_bytes savings_bytes savings_perc _time
I have no idea why the use of the eventtype foxes the distributed search - this could be a bug in Splunk.
... View more
02-19-2012
07:25 PM
This is most likely an artifact of domain name resolution rather than anything to do with Splunk.
Asking for the IP address of host.com may well give you different values at different times, for instance if there is more than one A record associated with the domain.
What specific problems does this cause you - perhaps if we know why you need the DNS lookup to remain consistent, your problem can be solved in a different way.
... View more
02-15-2012
06:16 PM
We have a licensing pool containing six servers, and we went over license last night.
Even though I've now installed a bigger license, and I've closed the licensing alerts many times today, I'm still getting three yellow bars at the top notifying me of the license violations. I really don't want to restart just to clear the alerts. I can't seem to make them go away via License Manager or any other screen.
... View more
02-13-2012
04:42 PM
Ah, it should be
LOOKUP-weblogic_access = calling_app s_account AS user OUTPUTNEW calling_app
... View more
02-13-2012
04:29 PM
1 Karma
With a little more digging, it seems that the lookup does work with the lookup command (one of the users that appears most in the logs isn't actually in the lookup table and so changes that improved the lookup appeared to have no effect until I dedupped the users).
However, it doesn't work with the automated lookup switched on:
Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'weblogic_access' and lookup table 'testlookup'
props.conf looks like:
[weblogic_access]
REPORT-weblogic_access = access-extractions
LOOKUP-weblogic_access = calling_app user AS s_account OUTPUTNEW calling_app
Actual CSV looks like
S_ACCOUNT,CALLING_APP
1234,userX
2345,userY
And we want to add a new field called calling_app based on the user field from weblogic_access, mapped to the s_account column in the lookup table (i.e. if user is 1234, calling_app should be userX)
... View more
02-13-2012
02:58 PM
Read access is provided for everyone, and the permissions are now set to Global, but still without success. I've renamed the lookup csv file to be the same as the transforms stanza, and inputlookup still works, but not piping the search results to lookup
... View more
02-13-2012
02:49 PM
the table lives in apps/$appname/lookups, the definition is in apps/$appname/transforms.conf, and the problem occurs when searching using the $appname app. No automated lookup as yet, but that would be in apps/$appname/props.conf
... View more
02-12-2012
05:04 PM
Have you looked at DELIMS rather than REGEX?
http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Createandmaintainsearch-timefieldextractionsthroughconfigurationfiles#Configuring_delimiter-based_field_extraction
Not sure how that would cope with the LOG at the start of the line, but I imagine you could always strip it off before DELIMS.
... View more
02-12-2012
04:43 PM
2 Karma
Lookup file testing.csv looks a bit like
user,username
1234,bob
2345,jim
3456,mary
In props.conf I have
[weblogic_access]
REPORT-weblogic_access = access-extractions
In transforms.conf I have
[testlookup]
filename = testing.csv
The inputlookup command shows that the lookup is being properly loaded, but a search of the form
sourcetype="weblogic_access" user != "-" | lookup testlookup user OUTPUTNEW username | table user, username
shows all of the users but the username column is blank. I have checked that the userids being looked up do exist in the lookup file!
What further troubleshooting can I do - ideally I'd like to get the lookup happening at search time with a LOOKUP-users stanza in props.conf but I suspect that fixing whatever is wrong here will correct the "Error in 'lookup' command: Could not find all of the specified lookup fields in the lookup table." message.
I get this problem whether I do it through the Manager or through the config files.
... View more
- Tags:
- lookup
02-12-2012
02:59 PM
That is confusing behaviour! Thanks for the explanation!
... View more
02-09-2012
04:56 PM
1 Karma
I can replicate this behaviour within a search head pool by
Add a Lookup Table, and upload a CSV file
Change permissions to be App
Note that location is now <sharedstorage>/etc/apps/<app>/lookups/<csvfile> (and not <splunkroot>/etc/apps/<app>/lookups/<csvfile>
Try to add a lookup definition, but the lookup table is not in the dropdown
If I add the lookup table to the <splunkroot>/etc/apps/<app>/lookups/<csvfile>, I can add the lookup definition
What I need is for the lookup definition dropdown to be able to find lookup tables under <sharedstorage>/etc/apps/<app>/lookups/<csvfile>
... View more