splunkninja

The dojo of Splunk. Learn, share, teach, mentor.

Ben Corbett
  • Male
  • London
  • United Kingdom
Share
Share on Twitter
Share on Facebook
 

Ben Corbett's Page

Gifts Received

Gift

Ben Corbett has not received any gifts yet

Give Ben Corbett a Gift

Latest Activity

After your comment on pulling out the src_ip I was ripping my hair out trying to find the field. I nthe end I did a sort of mash up with the rhost field that kind of did what I wanted but not exactly. It was confusing me becasue I wasn't exactly sur…
September 4, 2009
Ben... What do you find confusing about field allocation? Is the "Other Interesting Fields" concept that shows up in the blue sidebar?
September 4, 2009
Next up.... Make your own app.... I'll do a video on it, and you'll see why :)
September 4, 2009
Ben Corbett added a blog post
OK so I have finally upgraded to version 4.0 and now I am kicking myself that I didn't do it sooner! I mean I should have known that if someone known as the splunk ninja recommends you to upgrade your Splunk install then you REALLY should listen to…
September 4, 2009
A blog post by Ben Corbett was featured
Just looking at how to point our Isilon logs at Splunk. As of version 4.7.6 of OneFS, Isilon have implemented the function isi_log_server to specify a remote logging server Usage: isi_log_server COMMAND [ARGUMENTS ...] Commands: help Print this…
September 3, 2009
Ben Corbett added 2 blog posts
August 28, 2009
Hi Michael, I initially installed Splunk 4 but realised that it was the enterprise version with a time limit so therefore opted for the free version. I'm certainly looking forward to being able to upgrade to version 4 once the free release comes ou…
August 28, 2009
A blog post by Ben Corbett was featured
So I initially came across Splunk when seeing a banner ad on a blog site (may have been www.techrepublic.com) and I was inquisitive as to what the hell it was. After passing it over to a colleague to check out he informed me that it looked really gr…
August 27, 2009
Excellent Post. Recommendations. Upgrade to Splunk 4.x its like a monster truck rally (complete with flames) compared to the 3.x product. Field extraction (making structured sense out of those logs) is really easy to do. Next to each event (under th…
August 27, 2009
Ben Corbett updated their profile
August 21, 2009
Ben Corbett is now a member of splunkninja
August 21, 2009

Profile Information

Are you an existing splunk user?
Free
What do you do for your day job?
Technology Manager
Web / Blog Address
http://www.bruiza.com

Ben Corbett's Blog

Ben Corbett

Upgraded to 4.0

OK so I have finally upgraded to version 4.0 and now I am kicking myself that I didn't do it sooner! I mean I should have known that if someone known as the splunk ninja recommends you to upgrade your Splunk install then you REALLY should listen to him!

It would seem that the event segmentation works much better and now it is behaving how I would expect. I must admit that I was getting a little confused with the field allocation seemingly changing all the time but 4 seems to be solid as a rock.

Posted on September 4, 2009 at 12:06am — 3 Comments

Ben Corbett

Isilon Logs

Just looking at how to point our Isilon logs at Splunk. As of version 4.7.6 of OneFS, Isilon have implemented the function isi_log_server to specify a remote logging server


Usage: isi_log_server COMMAND [ARGUMENTS ...]

Commands:

help
Print this help and exit.

list
List all configured remote servers.

clear
Clear all configured remote servers.

add HOST [FILTER]
Add remote logging to hostname HOST. If logging is already
configured for HOST, the configuration will be replaced.
If
Continue

Posted on August 28, 2009 at 8:00am —

Ben Corbett

Installed Splunk a week ago and it's already proving useful

So I initially came across Splunk when seeing a banner ad on a blog site (may have been www.techrepublic.com) and I was inquisitive as to what the hell it was. After passing it over to a colleague to check out he informed me that it looked really great and we could definitely benefit from implementing it.

He set up the server but for a variety of reasons we never really embraced it. It wasn't until recently that I decided to dive in and check it out. I decided to ditch the VM that we had been u… Continue

Posted on August 27, 2009 at 10:48am — 2 Comments

Comment Wall

You need to be a member of splunkninja to add comments!

Join splunkninja

  • No comments yet!
 
 
 

Latest Splunk Community Postings

Loading feed

Latest Splunk Forum Posts

Loading feed

© 2010   Created by Michael Wilde.   Powered by .

Badges  |  Report an Issue  |  Terms of Service

Sign in to chat!