The venerable old-skool Splunk forums are now closed. Feel free to search for old content here, but new posts are no longer supported.
Instead, please visit the thriving community at answers.splunk.com to ask and answer questions about your Splunk deployment and how to get the most out of it.
Forums: Posted by bradhall
| Topic | Author | Replies | Latest Post |
|---|---|---|---|
|
New syslog agent
In: SplunkGeneral
Tags:
tools
syslog
Joe,
Just downloaded it and checked it out.. very cool! Hopefully a lot of people will find this ...
|
6
|
74 months ago... | |
|
can't get to http://foobar:8000
In: SplunkGeneral
(Not tagged)
Geoff,
You can get the ip address of your system using the "ifconfig" command; but if it is 68.81.81.252 ...
|
7
|
74 months ago... | |
|
Installer ignores install path directive
In: SplunkGeneral
(Not tagged)
Paul,
Can you send a tarball of your /opt/splunk/etc/* directory to support@splunk.com?
Thanks...
|
3
|
76 months ago... | |
|
Segfults on SMP boxes - update from your friends at Splunk
In: SplunkGeneral
(Not tagged)
Paul,
Email me... support@splunk.com, and we'll figure out the best way to get it over here.
T...
|
12
|
76 months ago... | |
|
Linux Instalation issue
In: SplunkGeneral
(Not tagged)
Make sure /tmp is not mounted noexec; thats usually the problem
|
4
|
77 months ago... | |
|
Splunk fails to start after system crash
In: SplunkGeneral
(Not tagged)
Paul,
If the system crashed you'll probably have to run "splunk recover" before it will start again. ...
|
7
|
77 months ago... | |
|
Loading...
In: SplunkGeneral
(Not tagged)
Bartos,
Upgrade to the 1.1.1 release that is now posted and see if that makes a difference.
-B...
|
1
|
77 months ago... | |
|
splunkd dumps core, Solaris
In: SplunkGeneral
(Not tagged)
John,
Can you send your log files from /opt/splunk/var/log/splunk* over to support@splunk.com? From ...
|
1
|
77 months ago... | |
|
hostRegex not working as expected
In: SplunkGeneral
(Not tagged)
Paul,
This will be working (as expected) in 1.1.1 (coming out in the next couple of days).
|
2
|
78 months ago... | |
|
FIFO and other stuff
In: SplunkGeneral
(Not tagged)
Gary,
We'll have a fix for the polling interval problem in the 1.1.2 release which will be out in ...
The syslog fifo stuff works pretty much out of the box with 1.1.1, just uncomment the path to the fifo ... Gary, Everything you need to make fifo's work will be coming with the 1.1.1 release. (Sometime in ... |
6
|
78 months ago... | |
|
Support Use Scenario: How to remove indexes & files?
In: SplunkGeneral
(Not tagged)
You can use the splunk clean command for #3: /opt/splunk/bin/splunk clean (after stopping the product)
Removes ...
|
2
|
78 months ago... | |
|
maillog 10 hours difference
In: SplunkGeneral
(Not tagged)
Bartoszx,
Thanks for the posts and all the info... please email me at support@splunk.com and we'll ...
Any chance the file got rolled and not picked up? |
5
|
78 months ago... | |
|
How are new data sourcetypes created ?
In: SplunkGeneral
(Not tagged)
Matt,
Send it over; we'll work with you on getting a setup that works with you file.
Thanks,
...
|
4
|
78 months ago... | |
|
Splunk wont stop
In: SplunkGeneral
(Not tagged)
Rick,
Sounds like if its not stopping that its stil eating data... how much data did you load into ...
|
3
|
78 months ago... | |
|
Unable to connect to search server at http://localhost:13489
In: SplunkGeneral
(Not tagged)
First check the config file (/opt/splunk/etc/myinstall/search.xml) and make sure that the port is set ...
Can you check netstat -an (while splunkd is running) to see if it is actually binding to that port? |
3
|
78 months ago... | |
|
Wrong time zone?
In: SplunkGeneral
(Not tagged)
The "ns" after the time is being taken as a US military timezone. This should be fixed in the next ...
|
1
|
78 months ago... | |
|
Can not Install/Start splunk on SLES8 (glibc 2.2.5)
In: SplunkGeneral
(Not tagged)
Probably not, any chance you can upgrade to glibc 2.3.4?
|
1
|
78 months ago... | |
|
Unable to connect to search server at http://
In: SplunkGeneral
(Not tagged)
Try installing 1.1 (that's the current build on the download page) and see if that solves the problem. ...
For the current (1.0.x) build that is posted you need NPTL to run the product... The build that should ... AiZ, do you have NPTL on the system? (you can check this with the command: getconf GNU_LIBPTHREAD_V... |
9
|
78 months ago... | |
|
Linux install doesn't
In: SplunkGeneral
(Not tagged)
Thanks for all the feedback from everyone; the 1.1.1 installer should not require tmp to be mounted ...
It's possible that it uses /tmp -- it's a bitrock installer so I'm not sure what they do internally... ... Gary, Try running the installer with "--mode text" and see if that works for you. Thanks, Bra... |
12
|
78 months ago... | |
|
Error starting FreeBSD version
In: SplunkAdministration
(Not tagged)
Alternatively you can just change the script to use #!/bin/sh -- we dont use anything bash specific ...
|
2
|
79 months ago... |