Sure... When you do group mapping, map them to groups that don't have the domain admins in them. I have a separate OU=Groups that has "Splunk Users, Splunk Admins, Splunk Power Users" as group names, and specific users…
I want to give LDAP access to my splunk servcie but I don't want the LDAP users to have admin capabilitys in Splunk. Can I keep the domain admins out of Splunk if I have LDAP authentication???
Helow Jonathan,
Glad to have another Splunker. I've been useing Splunk for 2 years and am hooked. I leared how to spell splunk and | transaction too. you'll learn that one soon.
Go over to Splunk…
Holy Batskins Ninja, zzzzzwap zgruppp kapow a hidden stash, how great is that!!!!
The team that found them must have special bat senses and highly tooned Splunking skills
I like to wear Extra Lovable…
Feb 7
Learning, learning, learning . . . Our Splunk "expert" is gone, and the non-programmer gets to learn the task! How do you spell SPLUNK?
Hello,If you can not install a Splunk Forwarder at your *NIX Systems, but you want to monitor this systems andinclude this systems in your Splunk *NIX App, read this Document.Monitor your NIX Systemes with no Forwarder.pdfregardsAlexander SzoenyiSee More
Hello,To give you a great start with Splunk, i hope i can help you with this short description, to build your own simple Apps.How to build a simple App for Splunk.pdfHave Fun ;-))best regardsAlexanderSee More
Hello,In the Forum are so many questions about installing Splunk in a environment.I have make a PPT for typical Scenarios for this questions.Splunk install Scenarios.pdfI hope it will be usefull.regards AlexanderSee More
Hello,
1. You can install so many FW you need, it is not a license question, you are only license Data/day for indexing at the Splunk Indexer.
2. You new scenario is correct.
3. If the customer do not want to invest in a new System for MS FW, use…
Hello,
What Linux do you have ?
If you have a rpm or dep you can make a remote install script for that.
example: rpm -i ftp://xx.xx.xx.xx/splunk.rpm
or dpkg -i ftp://xx.xx.xx.xx/splunk.deb
Please read also the documentation for ./splunk help
Or…
Hello,
For your POC, install a Splunk FW on a MS OS System and configure evt/evtx, WMI and ADMON.EXE.
you need for this max. 1 hour.
Install on the Splunk Indexer the Windows APP.
With this little tasks your POC is working ;-)))
regards Alexander
Hello,
1. You can export the evt and evtx, only to a Splunk with MS OS, because the evt and evtx are binarys and only on Windows you can transform this.
2. For WMI you need a Splunk Indexer with MS OS or a Splunk FW on MS OS, WMI works only on MS…
Hello,
Point 1
Go to the Search App -> Status -> Inputs Activity.
There you can find the "Most recently ignored files".
or use this search
index="_internal" source="*splunkd.log" earliest=-24h…
SPP is a Austria Company, based in Vienna. We over Services, Consulting, Development and License for Splunk in Austria, Hungary, Czech Republic, Slovakia, Slovenia, Ukraine and Rumania .