先熟悉一下架构: 下面去下载安装包:: install avilogic for splunk: Anvilogic App for Splunk | Splunkbase Step1: 1: install this avilogic app in the splunk web. 1.1 rename the media type to .tar.gz Anvilogi
今天处理了一个splunk 内存不足的case: Your search has been terminated. This is most likely due to an out of memory condition. Either edit your search to reduce memory requirements or contact your Splunk administr
今天实践了一把splunk 中inputs.conf 文件中的ignoreOldThan 的参数:就是上次的文件离今天很久了,要是再有Update 就不会被搜索到: 1: update one old file: taihumei.txt This file is old than many days ago, also I create a new file: info.txt [ro
1: 背景: 我们很多的app 有些需要在界面上面显示,有些app 在deployer 发布的时候,又有特殊的要求,那么这个时候,就需要app.conf 来发挥作用啦。 2: 举个例子: Deployer 发布app 到search head 的时候,有些是merge_to_default的,有的可能就是其他的: Use the deployer to distribute apps