Databases Reference
In-Depth Information
This form presents the global preferences that a user is allowed to change.
Other settings that affect users are configured through permissions on objects
and settings on roles.
Full name and Email address are stored for the administrator's convenience.
Time zone can be changed for each user. This is a new feature in Splunk 4.3.
Setting the time zone only affects the time zone used to display the data.
It is very important that the date is parsed properly when events are
indexed. We will discuss this in detail in Chapter 2 , Understanding Search .
Default app controls where you first land after login. Most users will want
to change this to search .
Restart backgrounded jobs controls whether unfinished queries should
run again if Splunk is restarted.
Set password allows you to change your password. This is only relevant
if Splunk is configured to use internal authentication. For instance, if the
system is configured to use Windows Active Directory via LDAP (a very
common configuration), users must change their password in Windows.
Search app
The search app is where most actions in Splunk start.
Data generator
If you want to follow the examples that appear in the next few chapters, install the
ImplementingSplunkDataGenerator demo app by following these steps:
1.
Download ImplementingSplunkDataGenerator.tar.gz from the code bundle
available on the site http://www.packtpub.com/support .
2.
Choose Manage apps… from the Apps menu.
3.
Click on the button labeled Install app from file. .
4.
Click on Choose File , select the file, and then click on Upload .
This data generator app will produce about 16 megabytes of output per day. The app
can be disabled so that it stops producing data by using Manage apps…, under the
App menu.
 
Search WWH ::




Custom Search