Splunk

Re-Index all data

2013-12-26 14:45
Do the following steps: 1) Disable the applications on the servers with Forwarders using the Deployment manager (or manually do so using the GUI) 2) On the Index server, stop Splunk and clean all event data for a given index: /opt/splunk/bin/splunk stop /opt/splunk/bin/splunk clean eventdata...

Disable splunk forwarder 8089 port

2013-12-12 15:52
$SPLUNK_HOME/etc/system/local/server.conf add the entry: [httpServer] disableDefaultPort = true