The venerable old-skool Splunk forums are now closed. Feel free to search for old content here, but new posts are no longer supported.
Instead, please visit the thriving community at answers.splunk.com to ask and answer questions about your Splunk deployment and how to get the most out of it.
Forums: Posted by ccan
| Topic | Author | Replies | Latest Post |
|---|---|---|---|
|
error when triggering script by a saved search
In: SplunkAdministration
(Not tagged)
Hi,
anybody seen this error message before?
I get this error in the splunkd.log everytime the saved ...
|
1
|
17 months ago... | |
|
detect security attacs
In: SplunkSearchAndAlert
(Not tagged)
Hi,
i need to build searches and mechanism to detect possible security attacs in the network.
Basically ...
|
1
|
25 months ago... | |
|
segmentation settings correct?
In: SplunkAdministration
(Not tagged)
Hi,
i have in the props.conf on my indexer following segmentation settings:
....
..
SEGMENTATION ...
|
–
|
28 months ago... | |
|
hostname extraction for different sourcetype
In: SplunkAdministration
(Not tagged)
thanks this works fine.
having your attention i would like to address another host extraction problem.
my ...
Hi, i have installed a light forwarder on one of my syslog server (B), forwarding to the main server ... |
3
|
28 months ago... | |
|
GUI speed
In: SplunkAdministration
(Not tagged)
Im using IE 7 on my office PC. the indexer is on a sun box.
Splunk box:
Solaris 10
8 UltraSPARC ...
Hi, although the new release 4.0 promised a beter speed and performance i still have a very slow GUI ... |
3
|
30 months ago... | |
|
extracted fields are not shown in the GUI
In: SplunkAdministration
(Not tagged)
Hi,
i have extracted a field (added regex to props.con and transform.conf) but i can not see it on ...
|
2
|
31 months ago... | |
|
WARN SavedSplunker - Maximum number (1) of concurrent scheduled searches reached. Skipping 4 ready-
In: SplunkAdministration
(Not tagged)
seems like this logs are produced permenantly. (There was another reason for my searches not running)
But ...
i have following situation: i have defined 3 different searches, where i run a script based on. my ... Hi, does anybody know where i can raise the number of concurrent searches? i have searches scheduled ... |
6
|
31 months ago... | |
|
syslogs from remote syslog server
In: SplunkAdministration
(Not tagged)
Thanks for the replies.
my problem is that i can not touch the syslog.conf on one of the syslog server.
so ...
Hi, I'm a new splunker and currently evaluating a suitable design for my company. i have currently ... |
4
|
31 months ago... |