The venerable old-skool Splunk forums are now closed. Feel free to search for old content here, but new posts are no longer supported.

Instead, please visit the thriving community at answers.splunk.com to ask and answer questions about your Splunk deployment and how to get the most out of it.

Forums: Posted by anon1m0us

Topics 1–20 of 55

Topic Author Replies Latest Post
Charting count of values for a field by another field
In: SplunkSearchAndAlert (Not tagged)
try the | transpose command
sshanabrook
Posts
3
26 months ago...
DeploymentClient - DeploymentClient is disabled.
In: SplunkAdministration (Not tagged)
What are the settings of your serverclass.conf?
I am assuming this file is on the client, not the server. Did you test the ports?
bmeshier
Posts
4
26 months ago...
Limit the Files that need to be indexed
In: SplunkAdministration (Not tagged)
Ok, I found the following to PURGE the old files: [main] frozenTimePeriodInSecs = 7776000 Anyway ...
Is there a way to limit the files that need to be indexed? Another words, I do not want to Index ...
anon1m0us
Posts
1
27 months ago...
Limit CPU
In: SplunkAdministration (Not tagged)
I found the following bug listed: · In 4.0.6 and earlier, running a LWF with deployment client ...
Is there a way to limit the CPU on a forwarder to use MAX 5% of the total CPU?
anon1m0us
Posts
3
27 months ago...
Lightweight Forwarder - Input Configuration
In: SplunkGeneral (Not tagged)
I have the following in my inputs.conf, which work. [WinEventLog:Application] disabled = 0 [WinEventLog:Security] disabled ...
gzebrasky
Posts
9
27 months ago...
SplunkLightForwarder
In: SplunkAdministration (Not tagged)
Can you provide the contents of your outputs & inputs.conf? Are you deploying the forwarder or you ...
splunkles99
Posts
7
27 months ago...
Display Results
In: SplunkAdministration (Not tagged)
Is there away to set the default to display 100 results in the UI, Splunk >> Manager » Searches and ...
anon1m0us
Posts
27 months ago...
Uprade from 4.0.2 -->4.0.5 broke Dashboard
In: SplunkReporting (Not tagged)
anyone?
I had a bunch of panels on my dashboard that used props.conf to extract IIS fields. Everything worked ...
anon1m0us
Posts
1
27 months ago...
forwarding/receiving and 4.x
In: SplunkAdministration (Not tagged)
Yea, I miss the topology too. However, try this command. It will tell you of all the Forwarders that ...
rgonzale6
Posts
3
27 months ago...
savedsearches.conf restarting service?
In: SplunkAdministration (Not tagged)
1) can i create a search and save it to my app's savedsearch? Right now it is being saved under my profile ...
anon1m0us
Posts
1
28 months ago...
Backslash and quotes
In: SplunkSearchAndAlert (Not tagged)
Did you try adding it manually to your savedsearches.conf?
bloizides
Posts
17
28 months ago...
^M in Unix server config files
In: SplunkAdministration (Not tagged)
hmm, no one else has this issue when deploying apps from Windows to *NIX?
I have a Windows Indexer pushing out apps to Unix servers. The problem is that after the push, all the ...
anon1m0us
Posts
1
28 months ago...
When to restart splunkd and/or splunkweb
In: SplunkApplications (Not tagged)
Check out this doc. http://www.splunk.com/base/Documentation/latest/Admin/Howyoucanconfigure If ...
jhart@edmunds.com
Posts
4
28 months ago...
forwarded box doesn't shot up
In: SplunkAdministration (Not tagged)
Did you configure the Indexer to listen on port 9997? Did you specify directories your outputs.conf ...
jritorto
Posts
1
28 months ago...
Can't see data in windows app
In: SplunkAdministration (Not tagged)
Do you use the correct index, like index=
marquetecken
Posts
2
28 months ago...
ServerClass.conf
In: SplunkAdministration (Not tagged)
Yes, the default works for WINDOWS servers. But how would I push it out to UNIX servers where the Default ...
The default targetRepository is $SPLUNK_HOME\etc\apps since the indexer is a Windows Server. Hence, ...
any help?
I have an application that uses Windows and Solaris servers. I installed Splunk on both. In the serverclass.conf, ...
anon1m0us
Posts
5
28 months ago...
fresh install of 4.05 crashes splunkd on windows 2003 64bit
In: SplunkAdministration (Not tagged)
I just upgraded with no issues.
haribhai
Posts
6
28 months ago...
Syslog
In: SplunkAdministration (Not tagged)
How do I forward them to the indexer? Is it via FTP or a program?
I have a Solaris 8 server with Splunk 4.0.2/4.0.4 Splunk does not support Solaris 8. How do I read ...
anon1m0us
Posts
3
28 months ago...
Eval 20 fields
In: SplunkReporting (Not tagged)
Is there a way to eval 20 fields without retyping "eval" and "where" 20 times? I have a report that ...
anon1m0us
Posts
28 months ago...
Multiple Directories having the same SourceType
In: SplunkAdministration (Not tagged)
Thanks! The docs only mentioned Subdirectories, so I was a little worried about different director...
Can I have multiple directories using the same sourcetype? We have application logs that are split ...
anon1m0us
Posts
2
28 months ago...
1    2    3    Next »