Unanswered Questions

3
votes
1answer
77 views

What does the warning in scheduler.log for Saved splunk failed to get current user context mean?

In reviewing the scheduler.log, I see the following warning. What does this mean? 06-03-2010 06:08:24.796 WARN SavedSplunker - Saved splunk failed to get current user context
3
votes
1answer
95 views

Deployment Server Log Entries Stopped

Somewhat odd behavior, my deployment server stopped generating log entries. I've been using the searches from http://answers.splunk.com/questions/2038/whats-the-best-way-to-monito …
3
votes
1answer
138 views

PDF App: An error occurred while generating a PDF of this report: Didn’t receive PDF from Report Server

Hello, I have a central splunk server, a splunk server specifically for the PDF Server application, and my mail server. When I run a report on SPLUNK-PDF it routes through the ma …
3
votes
0answers
38 views

App Wanted: Tomcat

There's an app on Splunkbase for WebSphere, but is anyone building a similar app for Tomcat?
2
votes
1answer
44 views

Changed the default permissions of newly created Saved Searches to be public?

Currently, when any of my users create a saved search, they are private. How can I alter that to be public? Also, is there a way to restrict which users have default public an …
2
votes
2answers
112 views

Adding intention to second drilldown search

Hi, I've got the advanced view below, which has the aim of producing a search-by-domain page for some Apache-like logs I've got Splunk indexing. The idea here is that there is a …
2
votes
1answer
57 views

Application scripts not executable when deployed via deployment server.

I'm having the same issue documented here http://www.splunk.com/support/forum:SplunkGeneral/3130 "An example is the Unix app. When this app is pushed to a Splunk instance using th …
2
votes
0answers
15 views

Fatal MetaData message re: sources.data in splunkd.log

I'm getting this error in splunkd.log on Windows 7 What does this mean and how can it be corrected? 08-15-2010 05:18:01.854 FATAL MetaData - failed to rename D:\SPLUNK\var\lib\sp …
2
votes
3answers
81 views

WinEvent Filtering on Heavy Forwarder

Hi, Trying to send all eventIDs from WinEventLog:Security to NullQueue with the exception of 592 and 593. Still getting all security events indexed :< props.conf and transfo …
2
votes
1answer
152 views

splunk integration with nagios

The initial splunk version we had was 4.0.x, we recently upgraded to 4.1.3 , since then our nagios alerts for splunk have started showing up, we use LDAP in our splunk base, the …
2
votes
0answers
73 views

Use googlemaps app instead of amMap for Cisco Security App?

Anyone tried to swap out the amMap flash map in the Cisco Security App and replace it with the new google maps app? How hard is it? How is the performance compared to the flash a …
2
votes
1answer
80 views

Can Splunk monitor a WebSphere Application Server cluster ?

We are trying to get Splunk to monitor a cluster of federated WebSphere Application Server v6.1 instances, which are centrally managed through a WebSphere Network Deployment (ND) A …
2
votes
2answers
40 views

Some events are merged when overiding multiple sourcetypes from single source

I am forwarding a single source (file) from kiwisyslog with LFW to the indexer, so got 1 sourcetype [kiwisyslog] Then I am overriding the hosts and sourcetypes. props.conf [kiwi …
2
votes
0answers
20 views

Suppress lookup table alert in Message module

What's the best way to preserve legitimate errors/warnings on a dashboard that uses |inputlookup to populate dropdowns or other UI elements, while suppressing the following message …
2
votes
1answer
86 views

External API for 4.1 - will my application still work?

Hi, I have a development support question. We have an application that is integrated with splunk. We have a C++ program that was written as a plugin (bundle or application now …

15 30 50 per page
1 2 3 4 5 28 next