The venerable old-skool Splunk forums are now closed. Feel free to search for old content here, but new posts are no longer supported.
Instead, please visit the thriving community at answers.splunk.com to ask and answer questions about your Splunk deployment and how to get the most out of it.
Forums: Posted by atyrsalvia
| Topic | Author | Replies | Latest Post |
|---|---|---|---|
|
Investigate offline logs ?
In: SplunkRequest
(Not tagged)
I'm not entirely sure what you're looking for, but if you haven't found help on this matter yet then ...
|
2
|
39 months ago... | |
|
Initial setup for File System Change monitoring?
In: SplunkAdministration
(Not tagged)
Contact support directly for troubleshooting help on this. The PCI Compliance App requires professional ...
|
1
|
40 months ago... | |
|
Report to trigger indexing
In: SplunkReporting
(Not tagged)
I don't think you can do that, though look into scripted inputs to see if that might help you find a ...
|
1
|
40 months ago... | |
|
Extracting certain fields from Apache Access log and write into a new log file
In: SplunkAdministration
(Not tagged)
I'm not sure exactly what you're looking to do. Maybe you'd be interested in checking out summary in...
|
1
|
40 months ago... | |
|
Unattended install
In: SplunkAdministration
(Not tagged)
Check out this page in our documentation:
http://www.splunk.com/base/Documentation/3.4.5/Installation/StartupOptions
--answer=yes ...
|
6
|
40 months ago... | |
|
My reports have stopped mailing
In: SplunkGeneral
(Not tagged)
What kind of authentication are you using? Did you suddenly add in LDAP or something similar?
|
4
|
40 months ago... | |
|
3.4.5 upgrade - causing server to hang
In: SplunkAdministration
(Not tagged)
You can contact support using the free version, though you are limited to email and web contact (we ...
|
5
|
40 months ago... | |
|
Add Timestamp at indexing time
In: SplunkAdministration
(Not tagged)
Are you interested in adding a timestamp from the local system rather than from within the logs?
|
1
|
41 months ago... | |
|
Admin user unable to modify other peoples saved searches
In: SplunkSearchAndAlert
(Not tagged)
breynolds is correct. You can also edit the search itself in the $SPLUNK_HOME/etc/system/local/savedsearches.conf ...
|
3
|
41 months ago... | |
|
Sources
In: SplunkAdministration
(Not tagged)
I wanted to give you a good answer on how we'll do this in 4.0, so I spent some time chatting with our ...
|
2
|
41 months ago... | |
|
How configure Splunk to display the correct character
In: SplunkAdministration
(Not tagged)
Unfortunately, Swedish is not a supported character set at this time. Here is a list of the supported ...
|
1
|
41 months ago... | |
|
License expired
In: SplunkPreview
(Not tagged)
Just to let you know, this should be up now.
Would you mind emailing splunkpreview@splunk.com with your question? That's the best place to direct ... Are you running the latest preview release? Preview licenses are for a fixed time and are specific to ... |
7
|
41 months ago... | |
|
doesn't report and display all the data
In: SplunkReporting
(Not tagged)
Can you post a sample of what the sar log looks like? (Feel free to anonymize the data if you need.)
|
2
|
42 months ago... | |
|
Error when extracting fields
In: SplunkGeneral
(Not tagged)
I think it would be best if you open a support case. We can help you manually extract these fields, ...
|
1
|
42 months ago... | |
|
Errors in Splunkd log
In: SplunkAdministration
(Not tagged)
Please file a support case on this issue. Thanks!
|
1
|
42 months ago... | |
|
Windows Management questions...
In: SplunkApplications
(Not tagged)
We've had a bug in one of the apps that caused a few reports not to show up as they should. Please file ...
|
2
|
42 months ago... | |
|
fschange on windows
In: SplunkAdministration
(Not tagged)
Go ahead and open a support case on this matter.
|
1
|
42 months ago... | |
|
Single Splunk instance for multiple business groups/multiple indexes/mergnng Splunk stores?
In: SplunkAdministration
(Not tagged)
Is there a reason you absolutely need to have separate Splunk instances for these groups, rather than ...
|
5
|
42 months ago... | |
|
How to map a source to a sourcetype?
In: SplunkGeneral
(Not tagged)
We at Splunk monitor this forum and make sure to respond, but support cases have first priority. Our ...
|
3
|
42 months ago... | |
|
Splunk for VMWare
In: SplunkApplications
(Not tagged)
Hello,
I think it would be best if you open a support ticket for this issue. I'd like to get some ...
|
3
|
42 months ago... |