Forums: Posted by pstein

Topics 1–20 of 23

Topic Author Replies Latest Post
Trying to match a search based on a like Number in two locations
In: SplunkSearchAndAlert (Not tagged)
...and I know I can match the string by doing the following but would rather have a shorter search....if ...
We are running v3.4.9....Hopefully Q1 will bring us up to v4.x
I have a search string that needs to be matched and only alert when the numbers in the string pair match. Example: local ...
pstein
Posts
3
2 months ago...
The need to search for a hosts defined "hosttag"
In: SplunkAdministration (Not tagged)
I am searching for a host but would also like to add in all the host's hosttag associated with it. A ...
pstein
Posts
1
4 months ago...
How to manage duplicate data entry into index - as designed from inputs.conf
In: SplunkAdministration (Not tagged)
**Thanks**....this is what I used to index data on the NAS by the server name and no others, removing ...
....ah come again!? Any type of example or link to this knowledge would be beneficial. Thanks.
I need to somehow get Splunk to use a variable in the dir path: [monitor:///n01/oraadmin1/diag/tnslsnr/$HOSTNAME] ...
Splunk v3.4.9 I have an oracle RAC cluster that has the following inputs.conf file [monitor:///n01/oraadmin1/diag/tnslsnr/] disabled=false _whitelist=.*\/(alert|trace)\/(log.xml|listener\_[\w]+\.log)$ crcSalt=<SOURCE> and ...
pstein
Posts
5
4 months ago...
Inputs.conf - Configuration Hmpph. One works while the next fails
In: SplunkAdministration (Not tagged)
....now that's what I am talking about //**Willis!**// /n01/oraadmin1/diag/tnslsnr ...
Yes....I am using this on a LightForwarder. I was unaware that you could break out multiple [source::.../<file>] ...
I am trying to index a log.xml file and have had NO luck unless I specify the full directory and file ...
pstein
Posts
4
5 months ago...
REGEX confusion. Tools say it works, but Splunk isn't buying
In: SplunkAdministration (Not tagged)
ChaChing!....with the forwarders in place and the messages coming from each forwarder the changes needed ...
With the changes above and a restart of Splunk on the indexing server I am still unsuccessful on removing ...
So here is what I have setup on my indexing server: Props.conf [oracle_host] TRANSFORMS-oracle_host=pruneoraclestatusmsg Transforms.conf [pruneoraclestatusmsg] REGEX ...
Like the other nullQueue entries, I put this on the indexer that was seeing the message. But, you may ...
Even though I doubt that would have any affect, I tried it and the same result. Splunk is still indexing ...
I have the following line I am trying to REGEX by pulling the following "sent status msg to all nodes" ...
pstein
Posts
8
6 months ago...
Removing Erroneous Host Names via CLI
In: SplunkAdministration (Not tagged)
I have no idea where the timestamps came from. All I know is they were being indexed on 03-01 and when ...
Yesterday we saw our host count rocket from ~6000 servers to over 24,000 servers and looking at the ...
pstein
Posts
2
9 months ago...
Formatting WAN output so it can be added to field for search or managed better
In: SplunkSearchAndAlert (Not tagged)
I have the following line from a WAN device and would like to understand how to better manipulate the ...
pstein
Posts
1
13 months ago...
Searching a specific IP shows multiple's not single as planned.
In: SplunkSearchAndAlert (Not tagged)
I am attempting to search via the UI for the following IP: 167.68.150.1 What I am looking for is "just" ...
pstein
Posts
2
13 months ago...
Sendemail.py - configuring server=
In: SplunkAdministration (Not tagged)
As always, **Spot on!** Thank you. PStein
I have looked through the docs and browsed the online sites to no avail. I have Splunk setup on my SuSE ...
pstein
Posts
3
14 months ago...
Is it possible to **NOT** have a passwd on login for a generic account?
In: SplunkAdministration (Not tagged)
I have a client that currently has a grep/awk tool for looking up LAN WAN data and also searching ACL's ...
pstein
Posts
1
18 months ago...
Splunk on SLES10 sp1 - (x86_64)
In: SplunkAdministration (Not tagged)
Found out it was actually the MIME type settings. Found under the ***known issues*** section from the ...
Is Splunk supported on ***SLES10 sp1 - (x86_64), Kernel 2.6.16.46-0.12-smp***? Currently when I install ...
pstein
Posts
2
18 months ago...
Multiple Indexes on single host and the ability to search against both in the same query
In: SplunkGeneral (Not tagged)
Thank you for following up. Please post this under Thomson Reuters. Love to see it in v4.0 major re...
I know you can setup multiple indexes for different types of data, but can you search against both in ...
pstein
Posts
5
18 months ago...
_whitelist for a dir and file in same path
In: SplunkAdministration (Not tagged)
Thanks. This helps, and I also determined using "splunk start --debug" to find out Splunk was reporting ...
Alex, Sorry this is dragging on so long but this is critical to getting our Oracle team onboard with ...
Keep in mind the bold setting in reply 11 is due to the asterisks in the data strings. Thanks.
This is a typical entry in the *.dat file pine:/u01/app/oracle/osw/archive/oswvmstat # more pine_vmstat_09.13.08.0900.dat zzz ...
Despite my ../bundles/local/props.conf file looking like this: # Adding in line for Oracle Data and ...
I don't know if it matters, but the way time was listed in my example was changed due to this GUI interface ...
A little follow-up. Now that I can get the _whitelist to expand and check the file list with ../splunk ...
ChaChing! The /.../ path wildcard did the trick. As always, ARaitz, you are ** the best!**
I am trying to build a _whitelist for a path and the second to last directory has multiple
pstein
Posts
16
19 months ago...
Scripted Inputs Not Running
In: SplunkAdministration (Not tagged)
Thank you for the clarification. That did it. Regards.
If I read that correctly, with 3.2.3 we should be putting the files in /opt/splunk/etc/bundles/default? And ...
...and another Follow-up. From Splunks own docs I found the following: http://www.splunk.com/doc/3.3/admin/inputsconfspec ../inputs.conf ...
Follow-up question: why do you add these entries to seperate inputs.conf and props.conf files and not ...
I have looked through previous forums and tried to modify what I have <see below> to match what as in ...
pstein
Posts
6
20 months ago...
Distributed / Data Forwarding - sending to DNS vs IP
In: SplunkAdministration (Not tagged)
I doubled back and added in DNS entry versus IP and yes, it works. IP is misleading and should be renamed ...
Thanks. I was using the Splunk GUI and it only has setting for IP setup. I will look further into where ...
No. I would like to send it to a DNS name....Splunk only offers the ability to send to an IP address...
I am trying to setup a pair of VCS servers and would like to push the engine_A.log to our production ...
pstein
Posts
7
21 months ago...
Reformatting Alert Notifications
In: SplunkAdministration (Not tagged)
Well....kind of. I am looking to reorder the data that we receive, but I don't want to have to write ...
When we capture a Live Search and an email goes out to our support groups they are requesting that I ...
pstein
Posts
3
21 months ago...
Directing client data to a new Data Store on Splunk Server
In: SplunkAdministration (Not tagged)
Patience Yago.......Patience. After waiting about 45 minutes I started to see the tails finally kick ...
I guess it was a short term solution. After believing it worked I doubled back and added the remaining ...
ARaitz, Considering that you need to edit the ../local/inputs.conf file in order to get the **index ...
ARaitz, This solved my issue. One simple heads up, after adding the "Oracle" Data Store the three ...
I have a client running Oracle and have the Splunk forwarding data from the client only to the Splunk ...
pstein
Posts
7
23 months ago...
How do I tail only *.txt files in a specified /dir vi GUI or CLI
In: SplunkAdministration (Not tagged)
I have a /dir that has both *gz files and *txt in it. I only want to add the couple hundred *.txt files. ...
pstein
Posts
1
24 months ago...
Non-essential process and how can I stop them in a Distributed Forwarding role
In: SplunkAdministration (Not tagged)
I have a client server that is simply forwarding smtp log data via **Splunk** and **Distributed Forward ...
pstein
Posts
1
24 months ago...
How to setup a search for # of hosts is 1 & # of events rises by "x"
In: SplunkSearchAndAlert (Not tagged)
ARaitz - Kachiga! Kachiga! (for those who have seen Cars, the Movie).....yes. That worked for this ...
With a live search setup to watch for memory errors in Solaris I get multiple hosts answering for the ...
araitz
Posts
5
25 months ago...
1    2    Next »