| Hi! Since upgrading to v.4.2 we have been having problems with going over our daily indexing volume limits. I have ... by jonathanward Explorer in Getting Data In 05-24-2011 2 5 | 2 | 5 | ||
| I'm seeing a lot of these lines in splunkd.log every 30 seconds from some forwarders : 05-24-2011 10:10:05.400 +020... by hexx Splunk Employee 3 1 | 3 | 1 | ||
| Every second or so splunk sends all the qualifying events it has see since it started plus any new events. Note: Thi... by bmorgan Explorer in Getting Data In 05-24-2011 1 1 | 1 | 1 | ||
| I'm getting similar messages that was posted in this question for a blocked AQ Is there a way to track down the sour... by williamsweat Path Finder in Getting Data In 05-23-2011 2 4 | 2 | 4 | ||
| I'm trying to extract domain info from the host field at search time and have the following props and transforms set,... by pmr Explorer in Getting Data In 05-23-2011 1 4 | 1 | 4 | ||
| I've been tweaking the *NIX app by adding some charts with queries such as: index="os" sourcetype="who" host=$host$ ... by FunPolice Path Finder in Getting Data In 05-23-2011 1 3 | 1 | 3 | ||
| Team, I'm cobbling together a Splunk app that monitors twitter and facebook data available through their APIs, and I... by sondradotcom Path Finder in Getting Data In 05-23-2011 2 2 | 2 | 2 | ||
| I am looking to set up a monitoring tool (HP's Sitescope) to "watch" our forwarders to ensure they are up. I am not ... by devonk Engager in Getting Data In 05-23-2011 2 1 | 2 | 1 | ||
| The ability for Splunk to start where it left off is a great feature. However, sometimes that feature hurts us. S... by seanlon11 Path Finder in Getting Data In 05-23-2011 3 6 | 3 | 6 | ||
| I have an input setup to monitor a folder where new log files get generated daily. Today however, a bad process gener... by zsimic Path Finder in Getting Data In 05-21-2011 0 1 | 0 | 1 | ||
| In your REST API documentation you have the following json example: // sample JSON output // https://localhost:8... by stevesq Explorer in Getting Data In 05-21-2011 0 3 | 0 | 3 | ||
| I setup splunk heavy forwarder and splunk indexer. I want to filter some event before indexed on splunk indexer. **... by anapat New Member in Getting Data In 05-21-2011 0 2 | 0 | 2 | ||
| I am interested in using Splunk! as an indexer, but would like to query other servers/controllers in the network for ... by traillz New Member in Getting Data In 05-20-2011 0 1 | 0 | 1 | ||
| I would like to expand the SAN volumes as we go along rather than carving out ALL of the volume I think I will need a... by maverick Splunk Employee 3 2 | 3 | 2 | ||
| We have a latency-sensitive application that must have latent-free logging output. The app is written to log out to ... by beaunewcomb Communicator in Getting Data In 05-20-2011 1 2 | 1 | 2 | ||
| I'm having trouble getting a host override to work. It appears Splunk is ignoring my transform (i assume because it's... by carmackd Communicator in Getting Data In 05-20-2011 1 4 | 1 | 4 | ||
| Hi, I'm using an UDP connection with syslog and Splunk. My problem is that Splunk only show me the firsts 2072 cha... by torbael Explorer in Getting Data In 05-19-2011 1 2 | 1 | 2 | ||
| I want to archive my frozen data to another location which is not on my indexers. Is the simple way to do this, to s... by johndunlea Explorer in Getting Data In 05-19-2011 1 3 | 1 | 3 | ||
| I've set up file monitoring with fschange: [fschange:C:\TEMP\test.txt] index = main recurse = false followLinks = fa... by kkuminsky Path Finder in Getting Data In 05-19-2011 0 1 | 0 | 1 | ||
| We currently have an in-line csv table lookup that is used in both summary and normal index searches. Due to the nee... by beaumaris Communicator in Getting Data In 05-18-2011 1 1 | 1 | 1 | ||
| Hello, I am extracting logs from the results of a screen scrape on Cisco load balancers. I used to use some Perl co... by jamesdon Path Finder in Getting Data In 05-18-2011 0 2 | 0 | 2 | ||
| Is there an app or collection of saved searches anybody has that would monitor and graph out all parts of the TCP con... by muebel SplunkTrust 3 2 | 3 | 2 | ||
| Hi Guys I have tried to install the universal forwarder on a jailed FreeeBSD 8.0 server but after running: pkg_add ... by wishlist Explorer in Getting Data In 05-17-2011 0 1 | 0 | 1 | ||
| I noticed while comparing the default configs for WMI and Perfmon that there's a LocalProcesses query in WMI that lac... by adamw Communicator in Getting Data In 05-17-2011 3 3 | 3 | 3 | ||
| If I recall correctly, there wasn't a way to set/offset the TZ for a syslog host. Has this changed? by the_wolverine Champion in Getting Data In 05-17-2011 1 3 | 1 | 3 |