sudo apt-get install python-software-properties
sudo add-apt-repository ppa:webupd8team/java
sudo apt-get update
sudo apt-get install oracle-java8-installer
tar -xvzf mysql-connector-java-5.1.39.tar.gz
cp mysql-connector-java-5.1.39/mysql-connector-java-5.1.39-bin.jar /opt/splunk/etc/apps/splunk_app_db_connect/bin/lib/
sudo update-alternatives --config java
OSX local dictionary is located in this file:~/Library/Spelling/LocalDictionary So if you by mistake added some misspelled word you can delete it from this file.Vadim
No DNS records are needed for a QNAME or Client-IP trigger. The name or IP address itself is sufficient, so in principle the query name need not be recursively resolved. However, not resolving the requested name can leak the fact that response policy rewriting is in use and that the name is listed in a …
Continue reading ‘RPZ qname-wait-recurse no’ »
wkhtmltopdf use 2 file descriptor per page (one each for header and footer) which are required for generating the per-page custom variables. By default Linux allows users to open up to 1024 files. So in case if your document contains more than 512 pages you have to change this limit up to a higher value. In Ubuntu …
Continue reading ‘wkhtmltopdf vs maximum pages’ »
This is a custom version of “DNS Top RPZ Hits” report with added Discovered Name/Network View fields and removed Time field.
This simple search shows IPAM network usage statistic.
index=ib_ipam sourcetype="ib:ipam:network" cidr<25
| streamstats dc(_time) as distinct_times | head (distinct_times == 1)
| table NETWORK address_total address_alloc address_unalloc
This is a custom version of this dashboard. I’ve added networks filter. The query for the filter is not an optimal in terms of performance but anyway will work good for small IPAM databases.
This report is a custom version of “Inactive IP Addresses” report and provide information about MAC addresses that were not connected to a network for a while.
This search shows Splunk’s version.
| rest /services/server/info | table splunk_server version