splunkninja

The dojo of Splunk. Learn, share, teach, mentor.

The SplunkNinja social network is a community for Splunk users, customers and enthusiasts. Share, learn and communicate. Freely.

Splunk Ninja Threads

Splunk Ninja T-Shirts

Since we're a community, we put together some logo wear which we hope everyone likes. It is available for purchase (with no profit) here.
Note: they're American Apparel. No crap here.

Latest Activity

1. A single Splunk index sits in a directory path. If you wanted to move Splunk's entire data store (All indexes), to a different Hard drive. Stop Splunk. Move the $SPLUNK_HOME/var/lib/splunk directory to another location. Edit the $SPLUNK_HOME/etc/…
18 hours ago
Thanks for your explanation... but i have one more question :) 1. when the HDD full, Splunk will stop indexing; How to tell Splunk to index data to another place (for example, to other PC in network or maybe to another HDD partition) ?. 2. if i s…
20 hours ago
Alexander Szoenyi was featured
yesterday
Retention Policy in splunk can be set on a per index basis, determined by the age of the data, or the size of the index (or i believe a combination of both). Most users store their data in the default index, known as "main" To change the retention…
yesterday
Jonesie is now a member of splunkninja
yesterday
Andi Susanto added a discussion
Hi,I wanna ask about indexing.For Example, if I have 10 GB HDD, and have Splunk 500 MB license; I set the max free space for Splunk to stop indexing when the free space of HDD is 2 GB (2000 MB) -- set from Manager - System Settings.  If one day, the…
on Friday
Hi, 1. Ok, clear.. 2. Thx. 3. It's hard to say to them, because the never want to install anything on their operational server. But I'll try... 4. I worry about this, because the POC has already running for 2 weeks, and if i suggest to change th…
on Friday
Hi Michael, thanks for reply, we need to pull all the event data directly from SCOM. Our client have many server that monitored by SCOM They really want to use Splunk to get the all server data that had pulled by SCOM. They want to combine, not…
on Friday
I'm also having terrible trouble getting Splunk to automatically import my logs. The log files are being sent by FTP to a local directory on the Splunk server. Splunk shows me the correct number of files in the Manager - Data Inputs - Files and Dir…
on Thursday
Andi... Is your hope to pull all the event data directly from SCOM? Or are do you just need to get eventlogs from each server?
on Thursday
radagent and Bobby Faber joined splunkninja
on Thursday
Alexander Szoenyi added a blog post
Hello, In the Forum are so many questions about installing Splunk in a environment. I have make a PPT for typical Scenarios for this questions. Splunk install Scenarios.pdf I hope it will be usefull. regards Alexander
on Thursday
Hello, 1. You can install so many FW you need, it is not a license question, you are only license Data/day for indexing at the Splunk Indexer. 2. You new scenario is correct. 3. If the customer do not want to invest in a new System for MS FW, use…
on Thursday
Hello, What Linux do you have ? If you have a rpm or dep you can make a remote install script for that. example: rpm -i ftp://xx.xx.xx.xx/splunk.rpm or dpkg -i ftp://xx.xx.xx.xx/splunk.deb Please read also the documentation for ./splunk help Or…
on Thursday
Andi Susanto added a discussion
Hi, i wanna ask if anyone has experience in get data from all windows server managed by SCOM (System Center Operations Manager)?Please guide me. Thanks
on Thursday
I really love Splunk slogan in APAC with Singaporean English : "Can can, cannot also can lah..." Please correct me; U have suggest us to provide (at least) one MS OS client installed and act as Splunk forwarder server that will collect all Events d…
on Thursday

Members

  • Jonesie
  • Michael Wilde
  • Andi Susanto
  • Alexander Szoenyi
  • Glenn Evans
  • radagent
  • James Fitzell
  • Bobby Faber
  • Hot Splunk
  • bizza
  • Keith Lawson
  • Atul Mistry
  • Betsy Schwartz
  • yanu pratomo
  • Mark Mendelson
  • Ziad
 

Forum

Andi Susanto

HDD full issue for indexing 3 Replies

Started by Andi Susanto in Help. Last reply by Michael Wilde 18 hours ago.

yanu pratomo

take log windows to splunk without forwarder 11 Replies

Started by yanu pratomo in Help. Last reply by Andi Susanto Feb 5.

Andi Susanto

Splunk with SCOM 2 Replies

Started by Andi Susanto in Help. Last reply by Andi Susanto Feb 5.

Blog Posts

Alexander Szoenyi

Install Scenarios for Splunk

Hello,

In the Forum are so many questions about installing Splunk in a environment.
I have make a PPT for typical Scenarios for this questions.

Splunk install Scenarios.pdf

I hope it will be usefull.

regards Alexander

Posted by Alexander Szoenyi on February 4, 2010 at 1:19am

Michael Wilde

Reverse DNS Lookups for Host Entries

When Splunk indexes, by default is going to take the hostname/ip that exists directly in the logfile entry...



Often, you would like to have the IP address resolved to a hostname, or vice versa. With Splunk 4.0 came a cool feature called "Lookups". Lookups allow for the… Continue

Posted by Michael Wilde on December 15, 2009 at 10:41am

Dave Jones

Configuring Apache as a reverse proxy to Splunk

My company has a demo VM running WebSphere Portal, and I also put Splunk on that server to help me troubleshoot it remotely much more efficiently. However, the only public traffic allowed into that VM is over ports 80 and 443.

That VM already has an instance of Apache (IBM HTTP Server actually) running, and the WebSphere plugin makes it function as a reverse proxy to WebSphere Application Server. It's configuration handles it's own set of URIs, so I needed to make Apache handle the ones for Spl… Continue

Posted by Dave Jones on November 16, 2009 at 6:46am — 6 Comments

Michael Wilde

Getting more intelligence on how much data splunk is eating.

As you know, there is a License pane in Splunk Manager (admin interface) that lets you know your "peak daily volume", and that figure is compared against your license volume. (free, or enterprise)

In the Splunk search app, (as of version 4.0.5) there is an "Index Activity" status dashboard in the search app (http://yoursplunkserver:8000/en-US/app/search/index_status). It does give you more information such as:


  • Top five sourcetypes (by total KB indexed) in the last 24 hours

  • In

Continue

Posted by Michael Wilde on November 6, 2009 at 8:24am — 1 Comment

Dave Jones

Using the websphere_trlog_sys* source types

Splunk has graciously included the websphere_trlog_sysout and websphere_trlog_syserr source types out of the box. They seem to handle the log entries very well.

However, due to the way IBM writes out these logs when they get rolled, you will also need to include the following line in your inputs.conf for your WAS logs:

crcSalt = <SOURCE>

Otherwise, Splunk will think it has already processed the log and ignore the new ones WebSphere AppServer creates. The Splunk docs describe the crcSalt… Continue

Posted by Dave Jones on October 2, 2009 at 11:00am

Groups

Notes

Killer Tech Links

Amazing VIM Tips - check this out.  I guarantee you will learn something sweet just by reading that page

Created by Michael Wilde Jan 7, 2010 at 8:26pm. Last updated by Michael Wilde Jan 8.

Why SplunkNinja, and why a community?

This is the SplunkNinja social network.  It has been setup to facilitate communication, learning, and transferrence of expertise on the Splunk IT Search engine.

While there are Splunk employees (past and present.. and maybe future) that are members, this network is not ran or moderated by Splunk, Inc.  It is "by the people.. for the people..."

I like the ninja concept because it denotes mystery, expertise, and getting the job done--which is what I hope all of you do, or are… Continue

Created by Michael Wilde Apr 18, 2009 at 10:17pm. Last updated by Michael Wilde May. 3, 2009.

 
 

© 2010   Created by Michael Wilde on Ning.   Create a Ning Network!

Badges  |  Report an Issue  |  Privacy  |  Terms of Service

Sign in to chat!