Databases Reference
In-Depth Information
This form presents the global preferences that a user is allowed to change.
Other settings that affect users are configured through permissions on objects
and settings on roles.
•
Full name
and
Email address
are stored for the administrator's convenience.
•
Time zone
can be changed for each user. This is a new feature in Splunk 4.3.
Setting the time zone only affects the time zone used to display the data.
It is very important that the date is parsed properly when events are
indexed. We will discuss this in detail in
Chapter 2
,
Understanding Search
.
•
Default app
controls where you first land after login. Most users will want
to change this to
search
.
•
Restart backgrounded jobs
controls whether unfinished queries should
run again if Splunk is restarted.
•
Set password
allows you to change your password. This is only relevant
if Splunk is configured to use internal authentication. For instance, if the
system is configured to use Windows Active Directory via LDAP (a very
common configuration), users must change their password in Windows.
Search app
The search app is where most actions in Splunk start.
Data generator
If you want to follow the examples that appear in the next few chapters, install the
ImplementingSplunkDataGenerator
demo app by following these steps:
1.
Download
ImplementingSplunkDataGenerator.tar.gz
from the code bundle
available on the site
http://www.packtpub.com/support
.
2.
Choose
Manage apps…
from the
Apps
menu.
3.
Click on the button labeled
Install app from file.
.
4.
Click on
Choose File
, select the file, and then click on
Upload
.
This data generator app will produce about 16 megabytes of output per day. The app
can be disabled so that it stops producing data by using
Manage apps…,
under the
App
menu.
Search WWH ::
Custom Search