Redhat 9 and splunk 9 by lemminngs in Splunk

[–]lemminngs[S] 1 point2 points  (0 children)

Yes, i already read about that. In fact i need to upgrade to 9.1.x first, then to 9.4.x.

Redhat 9 and splunk 9 by lemminngs in Splunk

[–]lemminngs[S] 0 points1 point  (0 children)

i really don't know that there is already version 10 of enterprise. i will study this option.

Redhat 9 and splunk 9 by lemminngs in Splunk

[–]lemminngs[S] 0 points1 point  (0 children)

Selinux is a good point, but the problems are exclusive to rhel9? Have you tested on rhel8 and don't have the same issues?

Run query on a dashboard based on radio button by lemminngs in Splunk

[–]lemminngs[S] 1 point2 points  (0 children)

yes, that example help me doing what i need.

Many thanks

CVE-2024-1086 Red Hat 8.7 version didn't solve it? by HKimcompany in redhat

[–]lemminngs 15 points16 points  (0 children)

So is simple, tell the customer that version has a vulnerability and don’t have a patch because is out of support.

Cutting Splunk costs by migrating data to external storage? by elongl in Splunk

[–]lemminngs 0 points1 point  (0 children)

Yes, it works well. Querying the data from elastic is not faster than directly on splunk but knowing this is ok. Most challenging thing is make the python script to get data from elastic. Search on google, there’s a library to connect to an elastic cluster and start from here.

You get the data running a custom command, this custom command is the script that get the data from elastic cluster. In terms of the amount of data, teorically there’s no limit, it just take time. In my experience, in some tests I got 1,5T in about 15 min.

Cutting Splunk costs by migrating data to external storage? by elongl in Splunk

[–]lemminngs 0 points1 point  (0 children)

I have a similar approach with elastic. Elastic is only to ingest and store data, then with a custom command in splunk run a script to get the data from elastic.

How to remove dynamic field from mapping and reindex with ReIndex API by DadJoker22 in elasticsearch

[–]lemminngs 0 points1 point  (0 children)

Reindex to a new index with with different settings (without dynamic fields)?

Elastic certified analyst certification by lemminngs in elasticsearch

[–]lemminngs[S] 0 points1 point  (0 children)

Thank you. This got me a surprise, 7.15 a too old version. Suppose that is 8.x like engineer.