<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Abi Rendon - Sysadmin &#187; syslog</title>
	<atom:link href="http://www.abirendon.com/index.php/tag/syslog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.abirendon.com</link>
	<description>The trials and tribulations of a web developer and sysadmin.</description>
	<lastBuildDate>Tue, 17 Aug 2010 00:44:19 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Splunk on SUSE with Firefox 3, forever loading&#8230;</title>
		<link>http://www.abirendon.com/index.php/2008/10/13/splunk-suse-firefox-forver-loading/</link>
		<comments>http://www.abirendon.com/index.php/2008/10/13/splunk-suse-firefox-forver-loading/#comments</comments>
		<pubDate>Mon, 13 Oct 2008 23:06:11 +0000</pubDate>
		<dc:creator>Abi Rendon</dc:creator>
				<category><![CDATA[Sysadmin]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[splunk]]></category>
		<category><![CDATA[suse]]></category>
		<category><![CDATA[syslog]]></category>

		<guid isPermaLink="false">http://www.azuretek.com/?p=71</guid>
		<description><![CDATA[If you&#8217;re using SLES or any other Suse variant you might be wondering why your Splunk installation is constantly in a loading loop unless you browse to it using Internet Explorer. After lots of hacking around, reboots and google searches I emailed the splunk team about my problem. At first they didn&#8217;t seem to understand [...]]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;re using SLES or any other Suse variant you might be wondering why your Splunk installation is constantly in a loading loop unless you browse to it using Internet Explorer. After lots of hacking around, reboots and google searches I emailed the splunk team about my problem. At first they didn&#8217;t seem to understand my problem but they did suggest I take a look at this article in their troubleshooting documentation.</p>
<p><a href="http://www.splunk.com/doc/latest/admin/UnableToGetAProperlyFormattedResponseFromTheServer">http://www.splunk.com/doc/latest/admin/UnableToGetAProperlyFormattedResponseFromTheServer</a></p>
<p><span id="more-71"></span></p>
<div class="ljcut">
It appears that there&#8217;s some kind of mime type issue where either the input/output is munged because SUSE incorrectly identifies it. It results in a &#8220;loading dashboard&#8230;&#8221; showing up for a long time and after that. </p>
<blockquote><p>Your search is still running after 1 minute. Unless you have set a high maxresults:: value, check if the Splunk Server is up and responding</p></blockquote>
<p>The fix is actually quite easy, I&#8217;ll just repost it here just in case the link I provided becomes bad later.</p>
<blockquote><p>
Unable to get a properly formatted response from the server</p>
<p>Users running Splunk on a SuSE 10.x server may receive the error message Unable to get a properly formatted response from the server; canceling the current search when executing any kind of search.</p>
<p>In order to resolve this issue edit /etc/mime.types. Delete (or comment out) these 2 lines:</p>
<blockquote><p>
text/x-xsl xsl<br />
text/x-xslt xslt xsl
</p></blockquote>
<p>Also change this line:</p>
<blockquote><p>
text/xml xml
</p></blockquote>
<p>to:</p>
<blockquote><p>
text/xml xml xsl
</p></blockquote>
<p>With these changes in place, restart Splunk and clear your browser cache.
</p></blockquote>
<p>Make sure to clear your cache, it&#8217;s actually quite easy! Just go to your firefox preferences underneath the &#8220;privacy&#8221; tag, there is a &#8220;clear now&#8230;&#8221; button.</p>
<p><img src="http://dl-client.getdropbox.com/u/49757/blog/clear_private_cache.png" alt="Firefox Clear Cache" />
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.abirendon.com/index.php/2008/10/13/splunk-suse-firefox-forver-loading/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My Job, Syslog, and Splunk</title>
		<link>http://www.abirendon.com/index.php/2008/09/29/syslogs-splunk/</link>
		<comments>http://www.abirendon.com/index.php/2008/09/29/syslogs-splunk/#comments</comments>
		<pubDate>Mon, 29 Sep 2008 09:19:33 +0000</pubDate>
		<dc:creator>Abi Rendon</dc:creator>
				<category><![CDATA[Sysadmin]]></category>
		<category><![CDATA[splunk]]></category>
		<category><![CDATA[syslog]]></category>
		<category><![CDATA[work]]></category>

		<guid isPermaLink="false">http://www.azuretek.com/?p=20</guid>
		<description><![CDATA[I have been working as the Senior Systems Engineer in the operations group at a company called Airbiquity for the past year or so.
As part of my daily job I come into contact with many new and interesting products and things that help me do my job better.
Firstly, how often do you find that you [...]]]></description>
			<content:encoded><![CDATA[<p>I have been working as the Senior Systems Engineer in the operations group at a company called <a href="http://airbiquity.com">Airbiquity</a> for the past year or so.</p>
<p>As part of my daily job I come into contact with many new and interesting products and things that help me do my job better.</p>
<p>Firstly, how often do you find that you need to constantly debug several machines at one? Tailing syslogs on each box can become a nightmare when you have more than one machine to look at. Consider these options&#8230;</p>
<ol>
<li>Configure your systems with syslog-ng to forward to a centralized syslog server where you can &#8220;tail -f&#8221; your problems easily.</li>
<li>Buy expensive products such as <a href="http://www.solarwinds.com/products/orion/SyslogServer.aspx">SolarWinds</a> syslog and snmp trap collector.</li>
<li>Use a free (500mb/day) syslog collector and search utility called <a href="http://www.splunk.com/">Splunk</a></li>
</ol>
<p>After messing with the SolarWinds products for a while I decided to move against it towards open source and free/cheaper options. </p>
<p>At Airbiquity I configured all of our servers and network equipment to send their syslog requests to a centralized syslog server. This was great for work debugging but I had trouble letting my boss have an easy utility that they could search with.</p>
<p>This is when I setup Splunk, it&#8217;s easy to install and while it can be load intensive it was a lot more intuitive and easy to use than the SolarWinds offering. So far it&#8217;s been great and we&#8217;re going to start looking into AD integration and clustering to support our multiple data centers.</p>
<p><span id="more-20"></span></p>
<div class="ljcut">
<p>Installing Splunk is as easy as pie, just download the RPM, they even provide a wget url.</p>
<p><img src="http://dl-client.getdropbox.com/u/49757/blog/splunk_download.jpg" alt="Splunk Download" /></p>
<p>Once you&#8217;ve downloaded just install using your flavor&#8217;s package system. They even provide a source version which you can install on any Linux distro, as well as an executable Windows version.</p>
<p>Redhat, SLES, etc.</p>
<blockquote><p>rpm -ivh &lt;yoursplunkdownload&gt;.rpm</p>
</blockquote>
<p>Ubuntu, Debian etc.</p>
<blockquote><p>dpkg -i &lt;yoursplunkdownload&gt;.deb</p>
</blockquote>
<p>Everything Else</p>
<blockquote><p>tar -xzvf &lt;yoursplunkdownload&gt;.tgz; cd &lt;newsplunkfolder&gt;;./install.sh</p>
</blockquote>
<p>
Once you&#8217;ve installed splunk you can enable auto start like so&#8230;
</p>
<blockquote><p>
/opt/splunk/bin/splunk enable boot-start
</p></blockquote>
<p>Pretty easy and you just run your new splunk init script to start it, you&#8217;ll then be able to connect to it using your servers url on port 8000.</p>
<p><code>http://&lt;yoursitesip&gt;:8000</code></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.abirendon.com/index.php/2008/09/29/syslogs-splunk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
