splunkninja

The dojo of Splunk. Learn, share, teach, mentor.

The SplunkNinja social network is a community for Splunk users, customers and enthusiasts. Share, learn and communicate. Freely.

Splunk Ninja Threads

Splunk Ninja T-Shirts

Since we're a community, we put together some logo wear which we hope everyone likes. It is available for purchase (with no profit) here.
Note: they're American Apparel. No crap here.

Latest Activity

8 hours ago
Patrick Swackhammer updated their profile photo
8 hours ago
Patrick Swackhammer added a discussion
Trying to test out the IMAP app, but when I go in to add a mail server and login name, then save, I get this error? Encountered the following error while trying to update: https://127.0.0.1:8089/servicesNS/nobody/imap/apps/local/imap/setup.   This w…
8 hours ago
Patrick Swackhammer and Eric Bradford joined splunkninja
8 hours ago
Michael Wilde and David Winter are now friends
yesterday
Well, if this is a common occurrence, I may want to look into developing an app for AS/400. In the meantime, I can post the script I made for my particular application. Simple bash (cause perl confuses me). #!/bin/bash cd ~/ echo accessing AS400 sf…
on Monday
If your script is "post-able".. that'd be great... the "AS/400 question" comes up often and users would like to benefit from your experience.
on Monday
Well, this is a down and dirty compliance stop gap. The log journals get spat out to text file every night, and then a cron job runs a script to pull them off the as/400 via sftp along with an MD5 sum file. The script then performs an md5sum on the…
on Monday
Question for you: How'd you get the logs from the AS/400. Arent they in EBCDIC, if so did you convert them? Whats your strategy for AS/400. Please share. (might even be blog post worthy!)
on Monday
on Monday
on Monday
haha, I was just about to come back and let you know I answered my own question. Thanks for all the help Michael!
on Monday
You are correct. Monitor a directory will work just fine. I user a single file to answer your challenge. Glad it worked for you!
on Monday
Awesome, it worked! One question though, for the monitor option in the inputs.conf, can I just leave the end of the path open ended to look in that directory for any new files? I see you put a file at the end, and am wondering if I'm a bit confused…
on Monday
on Saturday
This will work. First, create a props.conf in an appropriate directory (system level or app level), I'll make mine in $SPLUNK_HOME/etc/system/local/props.conf Add this to it: #my sourcetype will be called "as400" [as400] #I want splunk to bypass…
on Saturday

Members

  • Patrick Swackhammer
  • Eric Bradford
  • nicholas Lehman
  • Michael Wilde
  • Bob Osgood
  • Mike Ely
  • Pavan Krishnamurthy
  • April Jimmy
  • christophe le dorze
  • Mike Loven
  • Mohamed Elamin
  • Hagar
  • Dave Jones
  • Atul Mistry
  • Andi Susanto
  • Kung FuSchnickens
 

Forum

Patrick Swackhammer

Error installing IMAP App

Started by Patrick Swackhammer in General Questions 8 hours ago.

nicholas Lehman

Timestamping is the bane of my existance 10 Replies

Started by nicholas Lehman in Regex & Search-Time Field Extraction. Last reply by nicholas Lehman Mar 8.

Atul Mistry

Need Help with Automate Archiving 4 Replies

Started by Atul Mistry in Help. Last reply by Atul Mistry Mar 4.

Blog Posts

Alexander Szoenyi

Install Scenarios for Splunk

Hello,

In the Forum are so many questions about installing Splunk in a environment.
I have make a PPT for typical Scenarios for this questions.

Splunk install Scenarios.pdf

I hope it will be usefull.

regards Alexander

Posted by Alexander Szoenyi on February 4, 2010 at 1:19am

Michael Wilde

Reverse DNS Lookups for Host Entries

When Splunk indexes, by default is going to take the hostname/ip that exists directly in the logfile entry...



Often, you would like to have the IP address resolved to a hostname, or vice versa. With Splunk 4.0 came a cool feature called "Lookups". Lookups allow for the… Continue

Posted by Michael Wilde on December 15, 2009 at 10:41am

Dave Jones

Configuring Apache as a reverse proxy to Splunk

My company has a demo VM running WebSphere Portal, and I also put Splunk on that server to help me troubleshoot it remotely much more efficiently. However, the only public traffic allowed into that VM is over ports 80 and 443.

That VM already has an instance of Apache (IBM HTTP Server actually) running, and the WebSphere plugin makes it function as a reverse proxy to WebSphere Application Server. It's configuration handles it's own set of URIs, so I needed to make Apache handle the ones for Spl… Continue

Posted by Dave Jones on November 16, 2009 at 6:46am — 6 Comments

Michael Wilde

Getting more intelligence on how much data splunk is eating.

As you know, there is a License pane in Splunk Manager (admin interface) that lets you know your "peak daily volume", and that figure is compared against your license volume. (free, or enterprise)

In the Splunk search app, (as of version 4.0.5) there is an "Index Activity" status dashboard in the search app (http://yoursplunkserver:8000/en-US/app/search/index_status). It does give you more information such as:


  • Top five sourcetypes (by total KB indexed) in the last 24 hours

  • In

Continue

Posted by Michael Wilde on November 6, 2009 at 8:24am — 1 Comment

Dave Jones

Using the websphere_trlog_sys* source types

Splunk has graciously included the websphere_trlog_sysout and websphere_trlog_syserr source types out of the box. They seem to handle the log entries very well.

However, due to the way IBM writes out these logs when they get rolled, you will also need to include the following line in your inputs.conf for your WAS logs:

crcSalt = <SOURCE>

Otherwise, Splunk will think it has already processed the log and ignore the new ones WebSphere AppServer creates. The Splunk docs describe the crcSalt… Continue

Posted by Dave Jones on October 2, 2009 at 11:00am

Groups

Notes

Killer Tech Links

Amazing VIM Tips - check this out.  I guarantee you will learn something sweet just by reading that page

Created by Michael Wilde Jan 7, 2010 at 8:26pm. Last updated by Michael Wilde Jan 8.

Why SplunkNinja, and why a community?

This is the SplunkNinja social network.  It has been setup to facilitate communication, learning, and transferrence of expertise on the Splunk IT Search engine.

While there are Splunk employees (past and present.. and maybe future) that are members, this network is not ran or moderated by Splunk, Inc.  It is "by the people.. for the people..."

I like the ninja concept because it denotes mystery, expertise, and getting the job done--which is what I hope all of you do, or are… Continue

Created by Michael Wilde Apr 18, 2009 at 10:17pm. Last updated by Michael Wilde May. 3, 2009.

 
 

© 2010   Created by Michael Wilde on Ning.   Create a Ning Network!

Badges  |  Report an Issue  |  Privacy  |  Terms of Service

Sign in to chat!