The venerable old-skool Splunk forums are now closed. Feel free to search for old content here, but new posts are no longer supported.

Instead, please visit the thriving community at answers.splunk.com to ask and answer questions about your Splunk deployment and how to get the most out of it.

Forums: Posted by cpenkert

Topics 1–7 of 7

Topic Author Replies Latest Post
index settings using "auto" - what is my bucket size?
In: SplunkAdministration (Not tagged)
We are on 4.05 and are using the default of memPoolMB = auto in indexes.conf. Is there a way I can ...
cpenkert
Posts
22 months ago...
Indexing on search head - how?
In: SplunkAdministration (Not tagged)
I have a distributed environment with separate search head and index servers. Lately, I've been getting ...
cpenkert
Posts
12
24 months ago...
Event breaking
In: SplunkAdministration (Not tagged)
I have a log file which contains large amounts of data broken up by <HttpRequest> indicating the beginning ...
cpenkert
Posts
1
24 months ago...
Basic setup question
In: SplunkAdministration (Not tagged)
Excellent - thank you. I had the setup as outlined, however I had not put in the username/password ...
Despite having hundreds of pages of manuals and endless forums entries in front of me, I'm unable to ...
cpenkert
Posts
2
27 months ago...
Setting sourcetype in props.conf on a Windows server
In: SplunkAdministration (Not tagged)
This thing is determined to foil me :) What I thought would be a quick way to mark up my data has cost ...
I'll submit a case on this.
unfortunately, that doesn't work either. I tried another variation as well with the same results. ...
unfortunately no results from running the btool command. It seems difficult to find Windows specific ...
I tried both of these options, as well as removing the explicit sourcetype that I had set up in the ...
Most (nearly all) of the information that I'm finding for using a [source:: ] statement in the props.conf ...
cpenkert
Posts
11
27 months ago...
Form Search using hosttag
In: SplunkAdministration (Not tagged)
I figured it out: searchterms AND hosttag=$Host={static/html/hosttags.txt}$
I was able to use the "form searches with predefined values" portion to create the file that populates ...
Also to note is that we are on version 3.4.10, so I need to find a solution that will work in that v...
Yes, I have reviewed the documentation yet am confused on how to do what I am requesting. Any input? thank ...
I'm just starting to look at form searches, and one of the first ones that I am looking to create would ...
cpenkert
Posts
6
28 months ago...
TZ usage specifics
In: SplunkGeneral (Not tagged)
per my post, the host is set in the inputs.conf on the forwarder.
OK. I have the following in my props.conf (in \etc\system\local\props.conf) and the host name matches ...
cpen
Posts
11
30 months ago...