🚀 DevOps & SRE Certification Program 📅 Starting: 1st of Every Month 🤝 +91 8409492687 🔍 Contact@DevOpsSchool.com

Upgrade & Secure Your Future with DevOps, SRE, DevSecOps, MLOps!

We spend hours on Instagram and YouTube and waste money on coffee and fast food, but won’t spend 30 minutes a day learning skills to boost our careers.
Master in DevOps, SRE, DevSecOps & MLOps!

Learn from Guru Rajesh Kumar and double your salary in just one year.


Get Started Now!

Splunk Command Line Reference

How to add monitor in Splunk?
$ sudo ./splunk [add|edit|remove|list] [monitor|exex|tcp|udp|oneshot]
source - file, directory, scripted input, or socket to manage

How to remove monitor?
$ sudo ./splunk remove monitor /var/log/jenkins

How to set hostname?
$ sudo ./splunk add monitor /var/log/dmesg -hostname rajesh -index newindex
$ sudo ./splunk add monitor /opt/lampp/etc -hostname rajhost -index rajesh

How to upload to new index?
$ sudo ./splunk add monitor /var/log/dmesg -hostname rajesh -index newindex

How to upload a file?
$ sudo ./splunk add oneshot /var/log/applog	
$ sudo ./splunk add oneshot C:\Program Files\AppLog\log.txt
$ sudo ./splunk add forward-server <host>:<port> -auth <username>:<password>

Alternatively, if you have many forwarders, you can use an outputs.conf file to specify the receiver. For example:
[tcpout:my_indexers]
server= splunk_indexer.acme.com:9997

This command, <port> is the network port you want the receiver to listen on.
$ sudo ./splunk enable listen <port> -auth <username>:<password>
$ sudo ./splunk enable listen 9997 -auth <username>:<password>

This command below will also show which apps each setting is coming from.
$ sudo ./splunk cmd btool --debug inputs list

Permanently remove event data from an index by typing
$ splunk clean eventdata
$ splunk clean eventdata -index <index_name>
$ splunk stop
$ splunk clean eventdata 	# To permanently remove data from all indexes
$ splunk stop
$ splunk clean eventdata -index _internal -f # To permanently remove data from _internal

Remove all data from one or all indexes
$ splunk help clean

Remove an index entirely
$ splunk stop
$ splunk remove index main # cannot remove idx=main, is internal
$ splunk remove index <index_name>

Disable an index without removing it
$ splunk disable index <index_name>

Subscribe
Notify of
guest


0 Comments
Newest
Oldest Most Voted
Inline Feedbacks
View all comments

Certification Courses

DevOpsSchool has introduced a series of professional certification courses designed to enhance your skills and expertise in cutting-edge technologies and methodologies. Whether you are aiming to excel in development, security, or operations, these certifications provide a comprehensive learning experience. Explore the following programs:

DevOps Certification, SRE Certification, and DevSecOps Certification by DevOpsSchool

Explore our DevOps Certification, SRE Certification, and DevSecOps Certification programs at DevOpsSchool. Gain the expertise needed to excel in your career with hands-on training and globally recognized certifications.

0
Would love your thoughts, please comment.x
()
x