• Search
  • Dashboards
  • Browse
    • Sourcetype

      • _audit
      • _internal
      • access_combined
      • apache
      • audittrail
      • citrix:netscaler:syslog
      • Cron
      • crowdstrike
      • Dashboards
      • datamodels
      • DBConnect
      • Enterprise Security
      • eval
      • F5
      • Fun Stuff & Helpful Hints
      • Hack
      • Hygiene
      • IIS
      • Juniper
      • Linux Performance
      • linux_secure
      • Malware
      • Monitoring
      • Networking
      • opensense
      • opsec
      • osx_secure
      • Perfmon:Available Memory
      • Perfmon:CPU Load
      • Perfmon:Free Disk Space
      • Perfmon:Network Interface
      • postfix_syslog
      • Qualys
      • REST
      • RFQ – Request For Query
      • splunkd
      • Tenable
      • Uncategorized
      • Unix:Uptime
      • WinEventLog:Application
      • WinEventLog:Security
      • WinEventLog:System
      • WinRegistry
      • WMI:Uptime
    • Tags

      6.1.2 admin apache audit audittrail authentication Cisco Diagnostics failed logon Firewall IIS index indexes internal license License usage Linux linux audit Login Logon malware Network Perfmon Performance qualys REST Security sourcetype splunk splunkd splunk on splunk Tenable Tenable Security Center troubleshoot troubleshooting tstats Universal Forwarder users Vulnerabilities Web Traffic Windows Windows Audit Windows Security _audit _internal
  • Post New Query
  • Our Blog
  • Splunk Jobs
  • Search
  • Dashboards
  • Browse
    • Sourcetype

      • _audit
      • _internal
      • access_combined
      • apache
      • audittrail
      • citrix:netscaler:syslog
      • Cron
      • crowdstrike
      • Dashboards
      • datamodels
      • DBConnect
      • Enterprise Security
      • eval
      • F5
      • Fun Stuff & Helpful Hints
      • Hack
      • Hygiene
      • IIS
      • Juniper
      • Linux Performance
      • linux_secure
      • Malware
      • Monitoring
      • Networking
      • opensense
      • opsec
      • osx_secure
      • Perfmon:Available Memory
      • Perfmon:CPU Load
      • Perfmon:Free Disk Space
      • Perfmon:Network Interface
      • postfix_syslog
      • Qualys
      • REST
      • RFQ – Request For Query
      • splunkd
      • Tenable
      • Uncategorized
      • Unix:Uptime
      • WinEventLog:Application
      • WinEventLog:Security
      • WinEventLog:System
      • WinRegistry
      • WMI:Uptime
    • Tags

      6.1.2 admin apache audit audittrail authentication Cisco Diagnostics failed logon Firewall IIS index indexes internal license License usage Linux linux audit Login Logon malware Network Perfmon Performance qualys REST Security sourcetype splunk splunkd splunk on splunk Tenable Tenable Security Center troubleshoot troubleshooting tstats Universal Forwarder users Vulnerabilities Web Traffic Windows Windows Audit Windows Security _audit _internal
  • Post New Query
  • Our Blog
  • Splunk Jobs

Members

Profile picture of manderso

manderso

@manderso Active 3 years, 3 months ago
  • Activity
  • Profile
  • Posts
  • Personal
  • Mentions
  • Favorites
  • Profile picture of manderso
    3 years, 2 months ago

    manderso wrote a new post

    Displays sourcetypes being truncated on ingest, then on selection, shows the related _internal message & the an event that caused it to trigger.

    Data Issues
    Truncation, Date Parsing and Timestamp issues […]

  • Profile picture of manderso
    3 years, 6 months ago

    manderso commented on the post, Bucket Status Dashboard

    In reply to: manderso wrote a new post Shows status of buckets per indexer host, when they rolled from warm to cold, and cold to frozen. Gives a timechart and table of each, as well as detailed bucket names per index & […] View

    ever make it work or still broke?

  • Profile picture of manderso
    3 years, 8 months ago

    manderso wrote a new post

    I’ve been looking a while for something like this, and decided to make it myself. This relies on the tinv_software _inventory add-on found on Splunkbase, but you can do it without, if you feel like it. […]

  • Profile picture of manderso
    3 years, 12 months ago

    manderso commented on the post, Deployed application status

    In reply to: manderso wrote a new post Created this dashboard to see when or if an application was deployed successfully. Close to splunkninja’s query, this will also show if the host in question also restarted to apply the […] View

    Yeah, I didn’t try to exclude them, as they gave slightly different results than the apps w/out the “.”. Let me know how it works for you if you exclude them.

  • Profile picture of manderso
    4 years, 1 month ago

    manderso wrote a new post

    Created this dashboard to see when or if an application was deployed successfully. Close to splunkninja’s query, this will also show if the host in question also restarted to apply the new app.

     

    Deployed […]

    • Profile picture of manderso
      manderso replied 3 years, 12 months ago

      Yeah, I didn’t try to exclude them, as they gave slightly different results than the apps w/out the “.”. Let me know how it works for you if you exclude them.

  • Profile picture of manderso
    4 years, 10 months ago

    manderso wrote a new post

    Shows status of buckets per indexer host, when they rolled from warm to cold, and cold to frozen. Gives a timechart and table of each, as well as detailed bucket names per index & host.

    Bucket Status […]

    • Profile picture of manderso
      manderso replied 3 years, 6 months ago

      ever make it work or still broke?

  • Profile picture of manderso
    5 years, 9 months ago

    manderso commented on the post, Auditd hosts in all environments

    In reply to: manderso wrote a new post Shows the login activity to our linux environments, sudo commands per host and users. Admin Notes: index=main was changed to index=* due to not everyone using the same index. This […] View

    It’s written for 7.2.3. What do you see when you try and load one of the searches?

  • Profile picture of manderso
    5 years, 11 months ago

    manderso commented on the post, Build License usage by Group

    In reply to: manderso wrote a new post This was cobbled together from multiple searches I found. This search feeds the license and storage dashboard posted here: It relies on the Chargeback app for the customers.csv […] View

    Usage dashboard posted here: https://gosplunk.com/license-and-storage-usage-dashboard

  • Profile picture of manderso
    5 years, 11 months ago

    manderso commented on the post, License and Storage Usage Dashboard

    In reply to: manderso wrote a new post This relies on the search posted earlier: This will display storage and license usage broken down by groups, predefined in the chargeback app customers.csv License and Storage […] View

    Search posted here: https://gosplunk.com/build-license-usage-by-group/

  • Profile picture of manderso
    5 years, 11 months ago

    manderso wrote a new post

    This relies on the search posted earlier:

    This will display storage and license usage broken down by groups, predefined in the chargeback app customers.csv

    License and Storage […]

    • Profile picture of manderso
      manderso replied 5 years, 11 months ago

      Search posted here: https://gosplunk.com/build-license-usage-by-group/

  • Profile picture of manderso
    5 years, 11 months ago

    manderso wrote a new post

    This was cobbled together from multiple searches I found. This search feeds the license and storage dashboard posted here:

    It relies on the Chargeback app for the customers.csv form.
    index=_internal […]

    • Profile picture of manderso
      manderso replied 5 years, 11 months ago

      Usage dashboard posted here: https://gosplunk.com/license-and-storage-usage-dashboard

  • Profile picture of manderso
    6 years, 3 months ago

    manderso wrote a new post

    Shows the login activity to our linux environments, sudo commands per host and users.

    Admin Notes: index=main was changed to index=* due to not everyone using the same index. This dashboard has been tested for […]

    • Profile picture of SplunkNinja
      SplunkNinja replied 6 years ago

      gbr,
      I’m testing the xml and have no issues. Feel free to join our discord and let us know your issue! https://discord.gg/fFJhGPw

    • Profile picture of manderso
      manderso replied 5 years, 9 months ago

      It’s written for 7.2.3. What do you see when you try and load one of the searches?

    • Profile picture of unknow787
      unknow787 replied 10 months, 2 weeks ago

      How can I achieve this with no XML file? I have sourcetype and index but no XML file. I can’t us any Add on or ingest files. I have to use the sourctype and the index they provided to me that live in Splunk already. I am able to get visual, but no data is populating. Any help would be greatly appreciated

  • Profile picture of manderso
    8 years, 7 months ago

    manderso wrote a new post

    I didn’t like the CPU input from the Splunk TA Nix app, so I created this small ingest from top. The script takes a snapshot of the top command, and looks directly at the header:
    top -b -n 1 | sed -n ‘1,5p’
    and […]

  • Profile picture of manderso
    8 years, 9 months ago

    manderso wrote a new post

    The following query shows uptime of all systems over a certain period of time (days_uptime). Replace my indexes w/ yours.
     index=os OR index=idx_appdev sourcetype=Unix:Uptime OR sourcetype=”WMI:Uptime” |dedup […]

  • Profile picture of manderso
    9 years, 3 months ago

    manderso wrote a new post

    | rest splunk_server=local /services/apps/local | search update.version=* | table title version update.version
    If that Splunk has internet access, it’ll have the update.* fields filled with the latest version if […]

  • Profile picture of manderso
    9 years, 5 months ago

    manderso wrote a new post

    Another view for which splunk user can do what in your splunk environment
    | rest /services/authentication/users | mvexpand roles | table realname, title, roles, email | join roles [ rest […]

    • Profile picture of SplunkNinja
      SplunkNinja replied 9 years, 5 months ago

      Awesome query, thanks for sharing!

  • Profile picture of manderso
    9 years, 5 months ago

    manderso became a registered member

  • Home
  • Log In
  • Register
  • About GoSplunk
  • GoSplunk FAQs
  • Contact the GoSplunk Team
  • Splunk Website
  • Splunk Documentation
  • Splunk Answers

GoSplunk is not affiliated with Splunk Inc. in any way.

© 2019 GoSplunk
  • Privacy Policy
  • Terms and Conditions
  • Forgot Password?
sponsored