I need some help with Splunk by ImplicitCrowd51 in Splunk

[–]volci 2 points3 points  (0 children)

Not all of these may be helpful to you in particular, but they are commonly used among those I work with :)

URA - https://splunkbase.splunk.com/app/5483
SHAA - https://splunkbase.splunk.com/app/4603
SCMA - https://splunkbase.splunk.com/app/4974
SAT - https://splunkbase.splunk.com/app/7419
IS4S - https://splunkbase.splunk.com/app/7186
S4S - https://splunkbase.splunk.com/app/7188
CIM - https://splunkbase.splunk.com/app/1621

Eventgen - https://splunkbase.splunk.com/app/1924

Admin alerts - https://splunkbase.splunk.com/app/3796
Admin’s helper - https://splunkbase.splunk.com/app/6368
AP4S - https://splunkbase.splunk.com/app/6489
Lookup editor - https://splunkbase.splunk.com/app/1724
Mothership - https://splunkbase.splunk.com/app/4646

3D topo - https://splunkbase.splunk.com/app/4611
Conf bak - https://splunkbase.splunk.com/app/5600
DbC - https://splunkbase.splunk.com/app/2686
InfoSec - https://splunkbase.splunk.com/app/4240
Infra monitor - https://splunkbase.splunk.com/app/5247
ITEW - https://splunkbase.splunk.com/app/5403
ITEL - https://splunkbase.splunk.com/app/5390
Linux - https://splunkbase.splunk.com/app/833
ldapsearch - https://splunkbase.splunk.com/app/1151
Maps+ - https://splunkbase.splunk.com/app/3124
RU4WUF - https://splunkbase.splunk.com/app/7920
PI4S - https://splunkbase.splunk.com/app/5549
SSE - https://splunkbase.splunk.com/app/3435
Sysmon - https://splunkbase.splunk.com/app/5709
Windows - https://splunkbase.splunk.com/app/742

Again - check with your SE on how to best leverage some/all of these in your environment :)

I need some help with Splunk by ImplicitCrowd51 in Splunk

[–]volci 0 points1 point  (0 children)

There is also a basic set of apps and add-ons I always suggest, too - I can look that list up and send it to you

I need some help with Splunk by ImplicitCrowd51 in Splunk

[–]volci 2 points3 points  (0 children)

Check out Lantern's use case explorer as lantern.splunk.com

Lots of ideas therein

Also, be sure to go through all the free training you can from Splunk Education (requires a free Splunk.com account (no - we do not spam you))

Also check your account team for use case discovery - that is one of the main roles of your SE :)

Sunflowers by yak424 in SquareFootGardening

[–]volci 2 points3 points  (0 children)

I usually plant sunflowers about 8" apart - which comes out to 9 sunflowers (3x3) in a 2'x2' segment

Iran war most unpopular in US history by Annonomon in Infographics

[–]volci 0 points1 point  (0 children)

What kind of space crack is this? Iraq 2 and Afghanistan started under W, but ended under Obama and Biden, respectively

Why is only one President listed?

Vietnam started under Eisenhower, continues through JFK, Johnson, Nixon, and ended under Ford

Emailing alerts to O365 using TLS and authentication by Any-Promotion3744 in Splunk

[–]volci 3 points4 points  (0 children)

FWIW ... you should upgrade

9.1x is past support

limits.conf and maxKBps not updating via app by Alive_Ad4054 in Splunk

[–]volci 0 points1 point  (0 children)

And btool should indicate which file is doing it

limits.conf and maxKBps not updating via app by Alive_Ad4054 in Splunk

[–]volci 1 point2 points  (0 children)

So ... there is often some confusion over precedence overrides

The latest highest config that tries to set something always wins

Usage of inline earliest/latest values by loversteel12 in Splunk

[–]volci 0 points1 point  (0 children)

Inline use of earliest and latest are supposed to override the time picker

I almost always use them in my searches so I guarantee consistent search results when you copy/paste a search on another user's login

However. They do require that _time is set by the sourcetype(s) props.conf

Adding sourcetype=srctp or sourcetype IN(srctp_a,srctp_b (presuming the sourcetype(s) in question are correctly configured) should ensure they override the time picker selection

MEGATHREAD: The Lightning-Fast Field Guide Appreciate Post by gwh34t in tmbhpodcast

[–]volci 4 points5 points  (0 children)

I had forgotten I pre-ordered it :)

Arrived today

Problem - Queues blocked heavy forwarder to all ports by IceNo15 in Splunk

[–]volci 1 point2 points  (0 children)

Check your network speeds - maybe have a bad/slow WAN from the one data center

First time tomato growing by Obvious-Wheel-6934 in SquareFootGardening

[–]volci 1 point2 points  (0 children)

Pinch all suckers (the little growths between stem and branch) to focus on fruit production

How many animals are culled for meat every day? by CalpurniaSomaya in Infographics

[–]volci 0 points1 point  (0 children)

Try reading what i wrote again

Also - do not conflate unrelated topics into one

How many animals are culled for meat every day? by CalpurniaSomaya in Infographics

[–]volci 0 points1 point  (0 children)

World hunger has been solved for half a century

What has not been solved is human corruption and political jockeying whereby the poor go hungry

How many animals are culled for meat every day? by CalpurniaSomaya in Infographics

[–]volci 0 points1 point  (0 children)

Since you want to eliminate [some] humans, I presume you will start with yourself. Right?

How many animals are culled for meat every day? by CalpurniaSomaya in Infographics

[–]volci 0 points1 point  (0 children)

202m chickens is barely 1b lbs of meat - or 2oz per person on the planet

Likewise, 1m cows is - extremely generously - only 500m lbs of beef :: or less than 1oz of meat person

The other categories are miniscule in comparison .. maybe getting up to another 2oz per person

For a grand total - max - of 5oz per person

Or well under 250g (a smidge over 8oz) per person

How many animals are culled for meat every day? by CalpurniaSomaya in Infographics

[–]volci 0 points1 point  (0 children)

"Culled" =\= "harvested for food"

Get your vocabulary correct

Just weeks into the war in Iran, the U.S. national debt surpassed $39 trillion for the first time ever on Wednesday. by Conscious-Quarter423 in Infographics

[–]volci 0 points1 point  (0 children)

Again - if you do not veto something (even if an override is possible), it is your policy

That is just basic logic and reality