Web-based Configuration
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Contents
Web-based Configuration
Splunk 2.1 adds an extensive administrator's interface to its web interface.
Admin Interface
Click Admin at the upper left corner to see the new Admin area of the web interface. It has several tabs, each with multiple subsections:
Server
Access control and settings of your Splunk Server.
- Settings
- Basic Settings: set the server name, installation path and port for splunkd.
- Web Interace: toggle the web interface, set the http and https ports.
- Datastore: toggle data storage on splunk server, set host value, set datastore path, enter minimum free space.
- Control
Restart the Splunk server.
Data Inputs
Configure existing and add new data streams.
- All
Display and access to the following data inputs.
- FIles & Directories
Display and access configuration of each path that is being read by Splunk.
- FIFO Queues
Display and access configuration of each FIFO that is being processed by Splunk.
- Network Ports
Displays and access configuration of each port that Splunk is watching.
- Database Tables
Display and access configuration of each database that Splunk is reading from.
Splunk-2-Splunk
- All
A schematic view of Splunk-2-Splunk configurations.
- Receive Data
Toggle data receiving, set port for receiving Splunk-2-Splunk data.
- Forward Data
Toggle data forwarding.
- Distributed Search
Toggle distributed search participation.
Users
Display and edit current users; add new users.
Splunks
- Saved Splunks
Display and run current Saved Splunks.
- Live Splunks
Display and edit current Live Splunks.
- Alert History
Display all sent Live Splunk notifications.
License & Usage
- Current License
Display current license information.
- Download License
Access Splunk.com to purchase or download a new license.
- Change License
Paste in a new license.
Guided Setup
If you're new to Splunk, Guided Setup will pop up a tool to help you configure only the basic settings you need to get started with a new Splunk Server.
Restarting the Server
Some configuration changes require you to restart the server. The Splunk Server will post a notice to any admin accounts if it has changes which require a reboot. You can reboot from the Server -> Control section of the Admin interface.
Built-in Help
Each of the green section headers on the new Admin interface has a blue "i" button next to it. Click this button to pop up specific help for that section.
Configuration Files
Your configuration changes will be saved as a local bundle of config files. You can distribute this bundle to other servers to replicate your configuration. See the section on Bundles for details.
This documentation applies to the following versions of Splunk: 2.1 , 2.2 , 2.2.1 , 2.2.3 , 2.2.6 View the Article History for its revisions.