The venerable old-skool Splunk forums are now closed. Feel free to search for old content here, but new posts are no longer supported.

Instead, please visit the thriving community at answers.splunk.com to ask and answer questions about your Splunk deployment and how to get the most out of it.

Forums: Posted by splunkles99

Topics 1–8 of 8

Topic Author Replies Latest Post
removing data over 30 days old from index(s)
In: SplunkAdministration (Not tagged)
Hi Has anyone worked out how to remove data from splunk that is over 30 days old? I had a look ...
splunkles99
Posts
1
25 months ago...
Deploying SplunkLightForwarder to multiple servers
In: SplunkAdministration (Not tagged)
I'll answer this myself ;-) Yep you can do this...just saw the entries on the indexer change to the ...
I think I might know the answer to this already but can anyone confirm the following: Can you deploy ...
splunkles99
Posts
2
25 months ago...
Problem to Index Linux Auditd
In: SplunkAdministration (Not tagged)
OK cracked it Not sure if i's a bug or not but I was configuring the tcp port vi a the data inputs ...
Yep the index is there and I have mapped the admin user to it. I log on with the admin user account, ...
can you post you inputs.conf - I'm having similar issues - I can forward data from my splunklightforwarder ...
apardo
Posts
11
25 months ago...
Splunklightforwarder to index
In: SplunkAdministration (Not tagged)
Hi I have forwarding and receiving working fine now until I try to encrypt the forwarding connection ...
Not sure if i's a bug or not but I was configuring the tcp port vi a the data inputs link on the mgmt ...
does the system/local/inputs.conf override /SplunLightForwarder/local/inputs.conf?
if I search using index="main" source="tcp:7772" then I get the same data displayed so it looks ...
If I go to the launcher app and select port 7772 I see current data and the search in the search bar ...
OK cheers can you see anything wrong with this? /opt/splunk/etc/apps/SplunkLightForwarder/local/inputs.conf [monitor://usr/local/apache2/logs] disabled ...
sorry for the typos - what I'm asking is where do I set the index = indexname and how do I map the data ...
Hi Guys I have an issue where I can set up a splunklightforwarder to forward data to a reciever ...
splunkles99
Posts
9
25 months ago...
Intermediate cert chain installation
In: SplunkAdministration (Not tagged)
to get round the %20 issue you can put in a modrewrite rule with [EN] flags at the end - I had this ...
Had the same problem - you have to make sure that if your RP uses SSL then splunk also uses SSL - if ...
tnine
Posts
6
26 months ago...
Splunk Integration with SSO
In: SplunkRequest (Not tagged)
Brilliant Thanks!!
Hi Can you confirm if this worked in the end? I need to do something very similar and for me personally ...
malex
Posts
7
26 months ago...
Splunk with PAM and VAS
In: SplunkAdministration (Not tagged)
given up on this - moved to having an apache RP using SSL in front of splunk with splunk doing AD au...
Hi Does anyone know if it's possible to integrate Splunk with PAM looking up to VAS? I have looked ...
splunkles99
Posts
1
27 months ago...
SplunkLightForwarder
In: SplunkAdministration (Not tagged)
Chowned everything to splunk user and everything still works a treat - thanks guys
cheers guys -I have it running after redploying from scratch, leaving everything running as the root ...
OK the penny dropped and rolled away..you do need to have the whole thing started and then run the ./splunk ...
Hi Thanks for getting back to me. I think the penny is starting to drop - am I correct in thinking ...
Hi Complete newbie to splunk. I have looked through the admin doc and followed the instructions ...
splunkles99
Posts
7
27 months ago...