The venerable old-skool Splunk forums are now closed. Feel free to search for old content here, but new posts are no longer supported.
Instead, please visit the thriving community at answers.splunk.com to ask and answer questions about your Splunk deployment and how to get the most out of it.
Forums: SplunkApplications
| Topic | Author | Replies | Latest Post |
|---|---|---|---|
|
Error configuring imap app
(Not tagged)
Trying to test out the IMAP app, but when I go in to add a mail server and login name, then save, I get this error?
Encountered the following error while trying to update: https://127.0.0.1:8089/servicesNS/nobody/imap/apps/local/imap/setup.
|
4
|
12 months ago... | |
|
Squid-Proxy
(Not tagged)
Someone implement Splunk with squid proxy.
I need to create reports for example:
Page navigate by users
Top web page visit by user
Time navigate by user and bandwitch used
Time navigate by user in each page and bandwitch used
Top website visit
Top user
|
1
|
14 months ago... | |
|
Splunk for Cisco Security
(Not tagged)
Hi,
For past 2 days I was tweaking Splunk's Cisco application.I got it working, but have question regarding the threat map: after clicking on one of the threats I'm getting the following error:
500 Internal Server Error
TypeError: 'NoneType' object is unsubscriptable
This page was linked to ...
|
11
|
16 months ago... | |
|
Help with Cisco Firewall and IPS Add-on !!!
(Not tagged)
Can someone please explain why I don't see any events for Cisco ASA firewall and IPS sensor. I described the problem in the previous topic:
http://www.splunk.com/support/forum:SplunkApplications/4323
|
1
|
17 months ago... | |
|
Splunk For Bluecoat
(Not tagged)
Has anybody gotten this Application to work? I have indexed some BlueCoat data with the eventtype of bcoat_proxysg but none of the canned reports or searches work and none of the fields are extracted. I get a lot of "Splunk cannot find a job with an sid = false. It may have expired." messages when ...
|
20
|
18 months ago... | |
|
Snort app not detecting all individual events for file data input
(Not tagged)
Problem is the same than:
http://www.splunk.com/support/forum:SplunkGeneral/2285?p=1
But, in my case, I am reading directly from a file; so the changes in:
[source::udp:514]
SHOULD_LINEMERGE=true
BREAK_ONLY_BEFORE = ^.{3}\w{3}\s\d+\s\d+\:\d+\:\d+\s+\w+\s\[[^\]]+\]\s\[\d+\:\d+\:\d+
MAX_EVENTS ...
|
1
|
19 months ago... | |
|
NetBackup logs
(Not tagged)
Is if possible to use Splunk to investigate NetBackup server/client log files?
|
1
|
19 months ago... | |
|
AfterGlow
(Not tagged)
I've installed the AfterGlow app and have set everything up but when I launch the app I get the following message:
Splunk encountered the following unknown module: "AfterGlow". The view may not load properly.
Does anybody have any idea what I'm missing?
|
1
|
20 months ago... | |
|
Windows App use another indexer
(Not tagged)
Hi,
How can I configure the Windows Apps to use another indexer instead of the default index?
Thanks
|
–
|
20 months ago... | |
|
NIX Application is not working
(Not tagged)
Hi All,
I have enabled the NIX application and all the scripts are enabled but for df -h ,and other unix scripts i am not getting the data in the application (i mean no graphs and data coming up).Please let me know wont the NIX app fetch data from my host and show the graphs for disk spaces ...
|
1
|
21 months ago... | |
|
SimpleResultTable in HiddenPostProcess can not work
(Not tagged)
Hi,
I want to create a dashboard with 4 tables. I used a hidden search with 4 hiddenpostprocess(s). But all 4 tables can not display. When I change tables to charts, all work well. Any suggestions?
Thanks,
Dianbo
[Revised on Mon, 31 May 2010 04:18:22 -0700]
The version is 4.1.2.
|
–
|
21 months ago... | |
|
Lea-loggrabber with Checkpoint - logs not showing up in Splunk?
(Not tagged)
We have setup the lea-loggrabber for Checkpoint. The communication between splunk and the checkpoint appears to be fine - the configuration all went through as described in the instructions. When I execute lea-loggrabber.sh, I see all of the logs from the checkpoint. If I use the debug option with ...
|
–
|
21 months ago... | |
|
PDF Server
(Not tagged)
Hello,
I have a central splunk server, a splunk server specifically for the PDF Server application, and my mail server.
When I run a report on SPLUNK-PDF it routes through the mail server and shows up just fine. When I run the test on SPLUNK-MAIN the PDF shows up fine. However, whenever I schedule ...
|
1
|
21 months ago... | |
|
Splunk for Cisco Security Image Map
(Not tagged)
Hi,
i just updated Splunk for Cisco Security through SplunkBase and i see a strange behavior. When the job run at the schedule time, i see the home_threat_data.xml growing in size (during the job is running) at the end of the job, the file just cleat itself and only one entry remaing in the .xml ...
|
2
|
22 months ago... | |
|
Splunk server needs to host crossdomain.xml for Flex application
(Not tagged)
I have developed a Flex/Flash app that uses the Splunk REST API to retrieve search results. The Splunk server needs a crossdomain.xml (policy file) ideally at the root - https://localhost:8089 because this is where the app first looks for the file. The problem is that I'm not sure where to drop ...
|
–
|
22 months ago... | |
|
ExecProcessor
(Not tagged)
Hi
I've noticed that the ExecProcessor is complaining about a shared library that ships with Splunk. My app uses the system library /usr/lib and works fine and throws no errors if I invoke it from the CLI. When Splunk invokes my app, I assume Splunk is changing the library path, which will cause ...
|
5
|
22 months ago... | |
|
Ironport Web Security Appliance Logging
(Not tagged)
I have my WSA sending access logs to Splunk with the Cisco Security App and I have the logs sourcetype set to cisco_wsa. I have tried setting the access log format to Squid, Apache and Squid Details but nothing seems to work correctly for the Cisco Security App. I have run the pre-built searches but ...
|
–
|
22 months ago... | |
|
Cisco Fiirewall App Add On error(s)
(Not tagged)
I installed a few custom apps for Cisco. After enabling the app then restarting Splunk, I receive this error.
"500 Internal Server Error
TypeError: 'NoneType' object is unsubscriptable
This page was linked to from http://164.67.132.248:8000/en-US/app/launcher/home.
--------------------------------------------------------------------------------
You ...
|
2
|
22 months ago... | |
|
Cisco Security (specifically ASA)
(Not tagged)
Hello,
I'm pretty new with this software, and I'm in the process to evaluate it as well.
So, our first needs is PIX and ASA logs.
so, I'm using Windows, and I already installed Splunk and the apps as well, mainly the Cisco Security app (with ASA, Ironport together).
well, there is not much ...
|
5
|
22 months ago... | |
|
How to Create a Traffic Map in amMap?
(Not tagged)
Can somebody give me insight as to how to create a traffic map in the amMap Application? Thanks!
James E
|
–
|
22 months ago... |