Splunk 5.0's Report Accelerator, better than Summary Indexing?

Over the last 3 years, I've worked with nearly 100 clients as a Splunk Professional Services Consultant across all sectors of business and have seen Splunk grow first-hand from the back office system admin's life saver, to the Enterprise Big Data Engine that it is today.  Splunk's latest 5.0.1 release is nothing short of amazing.  They've done the impossible, again - and they did it with their renowned Splunk personality.  It broadens the meaning...


Keeping your Splunk Deployment Server Organized

Image courtesy of xe-pOr-ex/ FreeDigitalPhotos.net

The following post is for Splunk administrators that are already somewhat familiar with the Splunk Deployment Server, and the deployment of configuration app packages. The scenario: As a sysadmin, no matter how much effort goes into planning and organization, there is the possibility that one day you will no longer be able to easily group your servers simply by their hostnames or IP addresses. It may be the result of an emergency change ticket...


Organizing Your Splunk Shoe Rack (Defining Index Structures , Part 2 of 2 )

In my previous post, I went through the thought process of defining a Splunk index structure.  There aspects of defining this structure were covered: data access control, data retention, and search performance.  Now that we understand the case for a well-defined index structure and the different factors that drive it, let's go through a use case.

An extremely bright and talented system administrator at the Panda Shoe Company (fictitious) wanted to work smarter and...


Splunk Data Input Pipeline and Processors

Image courtesy of the Splunk on Splunk App

I was a recent attendee of Splunk’s worldwide user’s conference .conf 2012. It was held at the ultra modern and chic Cosmopolitan Hotel located in the heart of Las Vegas, Nevada.  Over 1000 people attended the conference and there were 90+ information sessions geared towards a wide range of Splunk user levels. At any given moment over the 3-day conference, there were 12-16 sessions going on at the same time. There was literally a world of knowledge being handed out to anyone who...


Organizing Your Splunk Shoe Rack (Defining Index Structures , Part 1 of 2 )

Image courtesy of: FreeDigitalPhotos.net

Your Splunk Shoe Rack

When splunking with a new customer, one the first things I review when auditing their environment is their index structure. Why? Well there's a lot you can tell about the maturity of a Splunk deployment based on this particular configuration. The old saying that Forrest learned from his mom comes to mind...

"Momma always says there's an awful lot you could tell about a person by their shoes. Where...


Monitoring Weblogic Environments

If you work with Oracle Weblogic Server(WLS) in an enterprise environment, then you likely have many managed servers, clusters, applications, and services that you have to keep an eye on. The clusters and instances in a Weblogic domain add to the complexity of the application infrastructure. So how is a Weblogic administrator supposed to keep track of the various applications and services running across several different domains and servers?  Currently, there are a few known existing resources and/or tools available that would be able to assist with monitoring as well as proactively...


The Seven Dwarfs of Data On-boarding in Splunk

In my time working with and using Splunk, I have learned a few tricks and tips to make the Splunk experience even better. This post assumes you are familiar with a few Splunk keywords. If you are having trouble following along, take a look at this link and look up the terms: http://docs.splunk.com/Splexicon. If you have never seen Splunk before, I suggest taking a look at the Splunk Tutorial to familiarize yourself with the product: ...


Syslog Collection with Splunk

www.freedigitalphotos.net

What is Syslog?

If you're familiar with IT system administration, syslog data is something you've most likely come across.  It's a standard used to log server, system, and device messages.  It was originally developed as part of the Sendmail project in the 1980's and has become the standard used for Unix-based systems and for network devices such as...


Then One Day It Happens...

Image: nokhoog_buchachon / FreeDigitalPhotos.net

You’ve joined an elite team of engineers and administrators tasked to oversee your company’s technological needs.  As your company’s ambitious marketing teams generate more and more buzz, you find that with each day your job circles increasingly around growing your business’s capacity.  Months go by filled with unhindered efforts in project completion.  You’ve helped double your web traffic, beef up your network, and revamp your monitoring system.  ...


Using the Visualization Editor to Create a Dashboard in Splunk 4.3

Hello world!  This is my first blog post with Function1 and I hope you find it useful. This post will give you an idea of how simple it is to use the new Visualization Editor in Splunk 4.3 to create a dashboard. This neat new feature is great because it simplifies the dashboard and panel creation process by allowing any user to create a custom dashboard without having to write any XML code and/or book time and consult with the IT guy! Each Splunk user can create their very own custom dashboard with panels that can include a table, pie chart, line graph, or a variety of other options with...


Stay In Touch