The venerable old-skool Splunk forums are now closed. Feel free to search for old content here, but new posts are no longer supported.
Instead, please visit the thriving community at answers.splunk.com to ask and answer questions about your Splunk deployment and how to get the most out of it.
Forums: Posted by boo
| Topic | Author | Replies | Latest Post |
|---|---|---|---|
|
How to monitor logs in other machine?
In: SplunkPreview
(Not tagged)
There are several ways you can achieve this.
1. setup a splunk forwarder. As you mentioned this is ...
|
8
|
53 months ago... | |
|
Spool vs. "Watch and Copy"
In: SplunkAdministration
(Not tagged)
I would suggest using the Tailing processor for this. Copy the files into a directory that you have ...
|
1
|
57 months ago... | |
|
IIS logs in Splunk
In: SplunkGeneral
(Not tagged)
Take a look at this document,
http://www.splunk.com/doc/3.0.1/admin/OverrideHost
it will explain ...
|
3
|
58 months ago... | |
|
Splunkd won't start
In: SplunkGeneral
(Not tagged)
Are there any files in your SPLUNK_HOME/var/log/splunk with the word crash in their filename. If there ...
|
1
|
58 months ago... | |
|
Locking test failed on filesystem
In: SplunkGeneral
(Not tagged)
Hi nspidle,
What filesystem are you running this on ? If you could give some information about the ...
|
3
|
58 months ago... | |
|
The whinge thread
In: SplunkGeneral
(Not tagged)
Hey,
So the hosts information is still on the dashboard, I'm assuming your talking about the first ...
Hi folks, Starting off a whinge thread for 3.0. Please post all the stuff that annoys you in the ... |
5
|
59 months ago... | |
|
LDAP lack of sub-tree searching is a problem.
In: SplunkRequest
Tags:
ldap
mmm the group filter thing looks like a bug.
I guess to get around that you'll have to stop the server ...
Ahh good stuff. Weird that you support LDAPv3 but the pagesize has to be set to 0. well at least it's ... K let me first clear up some of your assumptions. 1. We do support sub-tree searching. Flat trees ... |
6
|
59 months ago... | |
|
Active Directory Integration Example
In: SplunkGeneral
(Not tagged)
Oh also if you don't want to deal with us through forums you should try the IRC channel on EFNET #splunk.
The ...
Ugh crashes make me sad, that should never happen. I understand you are in the process of transferring ... mmmm, are there any ERRORs in the splunkd.log ? When you log in as the failsafe user and go to the ... The rolemapping section is a to map user roles into splunk. These roles contain the lists of users. ... in the etc/bundles/README there are two files auth.conf.spec and auth.conf.example. That would be a ... |
18
|
59 months ago... | |
|
Sucking config files in
In: SplunkGeneral
(Not tagged)
ugh this doesn't sound good, any chance I could get a sample of one of these config files. I'll
take ...
Hey Burana400, I believe if you try CHECK_METHOD = entireMD5 you'll have much better sucess. The ... |
12
|
59 months ago... | |
|
Running Splunk on a virtual interface?
In: SplunkGeneral
(Not tagged)
when you say splunkd is not running is that the message your getting from the UI.
The reason I'm ...
|
2
|
60 months ago... | |
|
Splunk Crashed my server.
In: SplunkGeneral
(Not tagged)
well there might be something in /var/log thats causing the problems. The stuff thats scans the directory ...
|
1
|
60 months ago... | |
|
ldap login with blank password
In: SplunkGeneral
(Not tagged)
There is no way to patch your system. This fix will be in the 3.0 GA release.
I put in a fix to make sure this can't happen, even if anonymous binds are allowed the module will ... Just one thing to check. In sun directory server isn't there an option to perform anonymous binds when ... |
5
|
61 months ago... | |
|
Error on Authentication Configuration
In: SplunkGeneral
(Not tagged)
you can turn back on splunk authentication by moving the file $SPLUNK_HOME/etc/bundles/local/auth.conf ...
|
4
|
63 months ago... | |
|
Help with LDAP auth
In: SplunkGeneral
Tags:
auth
ldap
Hi suarezry,
Your config looks ok, I'm not seeing anything that would cause any problems.
Did ...
|
1
|
63 months ago... | |
|
LDAP user authentication
In: SplunkRequest
(Not tagged)
Hey Cos,
It turns out that they haven't pushed the fix so it's not in beta 3. If you come into ...
Hey Cos, I think you may be running into a bug I fixed a few weeks ago. If you grab the latest version ... Hi Cos, Could you describe what happens in the gui when you save the form for the ldap authentication. ... Sorry don't know what you mean by other methods I've metioned. No there isn't a refresh interval. ... hey fidotas, The next beta release will support LDAP paging, by default it has a page size of 800. The ... yeah that happens when there are alot of LDAP users in the entry we are going through. Over the next ... Hey fidotas, Yeah your right, this is a limitation in teh current implementation. I will be changing ... Oh also if there is anything not in the list of features that you folks would like to see please let ... Hi Folks, The bind user is just there to retrieve the information on users and map their r |
31
|
64 months ago... | |
|
Splunk-2-Splunk over TLS/SSL
In: SplunkRequest
(Not tagged)
Yes the splunk-2-splunk feature will now support SSL connections.
It is in the beta currently but may ...
yeah we agree, the SSH tunnel was just a quick way to get something working, but having to admin the ... |
3
|
64 months ago... | |
|
index size disproportionate to raw data size?
In: SplunkGeneral
Tags:
disk
overhead
space
Hi,
mmm it does sound like it's eating them over and over alright.
Are there any errors in your ...
|
11
|
65 months ago... | |
|
Disk crashed; splunk now says database is malformed
In: SplunkGeneral
(Not tagged)
Derek,
If you still have the logs files around I would recomment doing a clean of the system
./splunk ...
|
3
|
67 months ago... | |
|
Database storage of splunk data
In: SplunkGeneral
(Not tagged)
no it is not possible to store the log information in a SQL database.
|
1
|
67 months ago... | |
|
RADIUS authenticaion
In: SplunkRequest
(Not tagged)
Hey wwwdrich,
LDAP will be in the 2.2 release, after that the plan I plan to add other authentication ...
Hey Savyer, We definately plan to add in RADIUS authentication it's just a matter of when. At ... |
5
|
67 months ago... |