splunkninja

The dojo of Splunk. Learn, share, teach, mentor.

The SplunkNinja social network is a community for Splunk users, customers and enthusiasts. Share, learn and communicate. Freely.

Splunk Ninja Threads

Splunk Ninja T-Shirts

Since we're a community, we put together some logo wear which we hope everyone likes. It is available for purchase (with no profit) here.
Note: they're American Apparel. No crap here.

Latest Activity

Ziad added a discussion
Is it possible to have a splunk light forwarder (with unix enabled) to send its logs to a seperate index on the splunk server? Thanks everyone :)
3 hours ago
Patrick Swackhammer added a discussion
I've tried and failed to extract the IP Address field such that it only includes sets of 4 numbers that are all separated by periods.  The built-in Splunk Regex pattern generator always seems to tag additional text or punctuation that makes it took…
16 hours ago
Ferry Leirissa updated their profile
on Sunday
Ferry Leirissa updated their profile photo
on Sunday
Ferry Leirissa and Chan YC joined splunkninja
on Sunday
Thank you for prompt reply. Please let me explain what I am doing. There are three steps to index result of a command on the remote network device. 1. Splunk execute following shell script every 300 seconds as scripted input. #!/bin/bash # /usr/bi…
on Friday
Takamasa... Can you give me a sample of the whole output that splunk is indexing... if you have control over the output, there are some "header commands" you can insert into the script to control how indexing happens... More details, more answers!
on Thursday
Lionel Hartmann updated their profile
on Thursday
We're running version 4.0.9, build 74233. Here's the contents of imap.conf: # 1.Splunk IMAP Bundle 2.IMAP connection and indexing configuration # 1.This file provides configures how the Splunk IMAP application connects to 2.the IMAP server, what…
on Thursday
Takamasa Sasaki added a discussion
I want to index result of command on remote network device. I understand that App "splunk for unix" can index result of statistics command such as "top", "ps" ,"vmstat". This App is useful when I index result of the command on the localhost, not rem…
on Thursday
Robert Jankovics, Michael Roth, Robert Richter and 4 more joined splunkninja
on Thursday
Robert Richter updated their profile
on Thursday
3 members updated their profile photos
on Thursday
wilhelm bogner updated their profile
on Thursday
on Thursday
March 10

Members

  • Dave Jones
  • Ziad
  • Patrick Swackhammer
  • Ferry Leirissa
  • Chan YC
  • Michael Wilde
  • Michael Roth
  • Takamasa Sasaki
  • Lionel Hartmann
  • Chris Siebert
  • Robert Jankovics
  • Robert Richter
  • wilhelm bogner
  • Stefan Baryakov
  • Eric Bradford
  • nicholas Lehman
 

Forum

Patrick Swackhammer

Regex For Identifying IP Addresses (To Extract Field) 1 Reply

Started by Patrick Swackhammer in Regex & Search-Time Field Extraction. Last reply by Patrick Swackhammer 16 hours ago.

Takamasa Sasaki

Need help with scripted input for remote network device 2 Replies

Started by Takamasa Sasaki in Cool Search Commands. Last reply by Takamasa Sasaki Mar 12.

Blog Posts

Alexander Szoenyi

Install Scenarios for Splunk

Hello,

In the Forum are so many questions about installing Splunk in a environment.
I have make a PPT for typical Scenarios for this questions.

Splunk install Scenarios.pdf

I hope it will be usefull.

regards Alexander

Posted by Alexander Szoenyi on February 4, 2010 at 1:19am

Michael Wilde

Reverse DNS Lookups for Host Entries

When Splunk indexes, by default is going to take the hostname/ip that exists directly in the logfile entry...



Often, you would like to have the IP address resolved to a hostname, or vice versa. With Splunk 4.0 came a cool feature called "Lookups". Lookups allow for the… Continue

Posted by Michael Wilde on December 15, 2009 at 10:41am

Dave Jones

Configuring Apache as a reverse proxy to Splunk

My company has a demo VM running WebSphere Portal, and I also put Splunk on that server to help me troubleshoot it remotely much more efficiently. However, the only public traffic allowed into that VM is over ports 80 and 443.

That VM already has an instance of Apache (IBM HTTP Server actually) running, and the WebSphere plugin makes it function as a reverse proxy to WebSphere Application Server. It's configuration handles it's own set of URIs, so I needed to make Apache handle the ones for Spl… Continue

Posted by Dave Jones on November 16, 2009 at 6:46am — 6 Comments

Michael Wilde

Getting more intelligence on how much data splunk is eating.

As you know, there is a License pane in Splunk Manager (admin interface) that lets you know your "peak daily volume", and that figure is compared against your license volume. (free, or enterprise)

In the Splunk search app, (as of version 4.0.5) there is an "Index Activity" status dashboard in the search app (http://yoursplunkserver:8000/en-US/app/search/index_status). It does give you more information such as:


  • Top five sourcetypes (by total KB indexed) in the last 24 hours

  • In

Continue

Posted by Michael Wilde on November 6, 2009 at 8:24am — 1 Comment

Dave Jones

Using the websphere_trlog_sys* source types

Splunk has graciously included the websphere_trlog_sysout and websphere_trlog_syserr source types out of the box. They seem to handle the log entries very well.

However, due to the way IBM writes out these logs when they get rolled, you will also need to include the following line in your inputs.conf for your WAS logs:

crcSalt = <SOURCE>

Otherwise, Splunk will think it has already processed the log and ignore the new ones WebSphere AppServer creates. The Splunk docs describe the crcSalt… Continue

Posted by Dave Jones on October 2, 2009 at 11:00am

Groups

Notes

Killer Tech Links

Amazing VIM Tips - check this out.  I guarantee you will learn something sweet just by reading that page

Created by Michael Wilde Jan 7, 2010 at 8:26pm. Last updated by Michael Wilde Jan 8.

Why SplunkNinja, and why a community?

This is the SplunkNinja social network.  It has been setup to facilitate communication, learning, and transferrence of expertise on the Splunk IT Search engine.

While there are Splunk employees (past and present.. and maybe future) that are members, this network is not ran or moderated by Splunk, Inc.  It is "by the people.. for the people..."

I like the ninja concept because it denotes mystery, expertise, and getting the job done--which is what I hope all of you do, or are… Continue

Created by Michael Wilde Apr 18, 2009 at 10:17pm. Last updated by Michael Wilde May. 3, 2009.

 
 

© 2010   Created by Michael Wilde on Ning.   Create a Ning Network!

Badges  |  Report an Issue  |  Privacy  |  Terms of Service

Sign in to chat!