Smart AnSwerS #9

Hello Splunk community and welcome to the 9th installment of Smart AnSwerS.

Once a month, we have a birthday Thursday at the office where our awesome Facilities team provides an abundance of sugary goodness to celebrate. Last Thursday, they ordered ice cream sandwiches from a local Bay Area company It’s It! Alas, I had to resist with all my power for the first time. I have 3 weddings to go to in the next 3 months and currently can’t fit my slacks. *sobs in a dark corner* On the brighter side of things, I’ve been feeling more energized and focused than ever to bring you these topics which, by the way, were all asked and answered by members of our very own Splunk Support team! Customers come across some very interesting issues and use cases that can prove useful to many others, so we bring it to you on Splunk Answers. – Check out this week’s featured posts:

How can I get a complete list of processes used by Splunk for Linux?

cwl was working with a customer that needed a way to identify all Splunk related processes for Linux in their environment to avoid stopping them by mistake. The ever so knowledgeable hexx provided his recommendation of searching against Splunk’s introspection logs and how to do this.
http://answers.splunk.com/answers/210629/how-can-i-get-a-complete-list-of-processes-used-by.html

How to change permissions on Splunk log files?

dshakespeare_splunk introduces a requirement to monitor Splunk logs with other applications and the need to change the file permissions before doing so. He tags himself out from asking the question and tags himself right back in to answer it with the step-by-step that has worked for some customers.
http://answers.splunk.com/answers/209239/how-to-change-permissions-on-splunk-log-files.html

How to troubleshoot Search Head Clustering initial bootstrap failing with error “found different peer with serverName and hostport already registered and UP”?

rbal_splunk is a regular when it comes to finding common issues customers are facing and bringing the solutions to Splunk Answers. While trying to bootstrap 3 search head cluster members, an error occurred showing a conflict with a peer already registered with a serverName and hostport. It was found that all SHC members were installed using the same image resulting in the same GUID. rbal_splunk covers the process that resolved this issue.
http://answers.splunk.com/answers/210634/how-to-troubleshoot-search-head-clustering-initial.html

Thanks for reading folks and have a great rest of the week!

 

Missed out the first eight Smart AnSwerS blog posts? Check em out here!
http://blogs.splunk.com/2015/01/29/smart-answers-8
http://blogs.splunk.com/2015/01/21/smart-answers-7
http://blogs.splunk.com/2015/01/15/smart-answers-6
http://blogs.splunk.com/2015/01/08/smart-answers-5
http://blogs.splunk.com/2014/12/30/smart-answers-4
http://blogs.splunk.com/2014/12/18/smart-answers-3
http://blogs.splunk.com/2014/12/03/smart-answers-2
http://blogs.splunk.com/2014/11/24/smart-answers