Documentation: 3.1.4
Print Version Contents
This page last updated: 05/21/07 01:05pm

Getting Started

How do I start?

If you haven't installed Splunk yet, read the Installation Manual. If you've already installed it, point your browser at port 8000 on your server. If you have an enterprise license, you will need to login with the default username "admin" and password "changeme."

I just installed Splunk with an enterprise and I'm trying to log into the web interface for the first time. It's asking me for a username and password. What are they?

The default username is "admin" and the password is "changeme."

How do I index a file?

Log into the Splunk web interface as an administrator and click on the "Admin" link at the top left. Then click on data inputs and follow the interface instructions from there.

Alternately, type $SPLUNK_HOME/bin/splunk help input for assistance with adding data via the commandline.

I've gotten to my Splunk interface, but what do I search for?

You should have a list of source types and hosts and sources toward the middle of your Splunk home page. Choose one, click and you will see all associated events.

Or you can open the Splunk drop-down menu at the top of the UI. Hover over "Saved Splunks" and choose "all." This search will return every event (up to the 10,000 most recent) in your Splunk index.

Can I install a new version of Splunk over an older version, without losing any of my configurations or data?

Yes. See the Installation Manual for instructions.

Previous: Customers and Partners    |    Next: Accessing Data

Comments

No comments have been submitted.

Log in to comment.