Getting Data In

Failed Logs starting at 12am and ending at 11:59pm

New Member

Hello,
I am using the free version of the splunk and I just want to see the days log files from all the servers I have in my remote event log collections. Is there a way to store the old ones per day as well?
I would like to start the logs from today and not from when the day the servers were turned on?

Is there a way to get these things done?

Thank you,
Josh

Tags (3)
0 Karma

Splunk Employee
Splunk Employee

if you plan to produce daily logs every day then you end up indexing the whole event history. Then there is no need to do "day filtering", but instead you can build views which show only today's events.

0 Karma

SplunkTrust
SplunkTrust

Hi Joshbiz

I can think of two ways you could achieve this:

  1. splunk reads all what there is in a log files, so if the log file only contains today data when you start splunk you will get only todays data.
  2. route older data to the null queue, you can filter and route any older data to the null queue this way it will not be indexed. read more in the docs

hope I got your question right and it helps a bit....

cheers

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!