Getting Data In

Getting Data In
Community Activity
krusty
Hi, is it possible to use different indexes on the main splunk server which received the data from windows forwarde...
by krusty Contributor in Getting Data In 03-25-2011
1 8
1
8
tpsplunk
I have a handful of different sourcetypes that all get written to log files in /var/log/app. I also have more than o...
by tpsplunk Communicator in Getting Data In 03-24-2011
3 13
3
13
spock_yh
I have the following stanza in transforms.conf: [medusa_media_access-drop-events] REGEX = ^\S+\s++\S+\s++\[[^\]]*\]\...
by spock_yh Path Finder in Getting Data In 03-24-2011
0 2
0
2
michaelhobbs
I'm having a heck of a time figuring out the best way to get splunk to show these multiline events in one event. Any ...
by michaelhobbs Explorer in Getting Data In 03-24-2011
1 7
1
7
the_wolverine
I have DNS log lines that look like the following: (4)mail(6)google(3)com(0) (7)twitter(3)com(0) (12)spreadsheets(1)...
by the_wolverine Champion in Getting Data In 03-24-2011
0 5
0
5
spatil
Hi , I have below configuration in inputs .conf [monitor:C:\Program Files\Splunk\etc\apps\sampleApp\samplelogs] I h...
by spatil Path Finder in Getting Data In 03-24-2011
0 1
0
1
dmlee
Hi, as we know , before splunk eat a compressed file, splunk will decompress it first then index it. but, if we ha...
by dmlee Communicator in Getting Data In 03-24-2011
1 2
1
2
splunktp
I have a Splunk 4.1.7, build 95063 instance and am trying to pull logs from Informix DB on Solaris 10. So I had set t...
by splunktp Explorer in Getting Data In 03-24-2011
0 1
0
1
Rayj00
Totally new with Splunk. Have mercy on my soul!  I am trying to set up Splunk on my laptop as I am awaiting licens...
by Rayj00 New Member in Getting Data In 03-23-2011
0 2
0
2
rayjsplunk
Is a Splunk Agent the same as a Splunk Forwarder? Thanks, Ray
by rayjsplunk New Member in Getting Data In 03-23-2011
0 3
0
3
Mr_Robaloba
I tried out the option "source name override" when setting up a UDP data input to replace "UDP:514" with "mynetworkSy...
by Mr_Robaloba Explorer in Getting Data In 03-23-2011
1 3
1
3
Mr_Robaloba
I am trying to filter a log file coming in via a universal forwarder (both installs are 4.2) so that messages contain...
by Mr_Robaloba Explorer in Getting Data In 03-23-2011
0 2
0
2
DTERM
I have a simple setup. A light forwarder, forwarder and an indexer. The light forwarder stopped working about 5 day...
by DTERM Contributor in Getting Data In 03-23-2011
0 3
0
3
ickymettle
Hi Splunkers, We have a macro here we're using to allow users to search their previous search history. It relies on ...
by ickymettle Explorer in Getting Data In 03-23-2011
1 1
1
1
seanlon11
I have about 50 forwarders in my environment. Somewhere I have screwed up, and included the same set of host data tw...
by seanlon11 Path Finder in Getting Data In 03-22-2011
0 1
0
1
bkaspar
We just updated to 4.2 on our splunk server, and I am in the midst of pushing the Universal Forwarder out to replace ...
by bkaspar Engager in Getting Data In 03-21-2011
1 2
1
2
hochit
Is it necessary to use si* command for summary index and we need to make it as scheduled save? Since I recall the sa...
by hochit Path Finder in Getting Data In 03-21-2011
2 2
2
2
fox
A new type of log file has been added to an existing data input by amending the whitelist and blacklist. (new data in...
by fox Path Finder in Getting Data In 03-21-2011
2 2
2
2
Jason
I have a forwarder that appears to be a LWF (SplunkLightForwarder app is enabled) however I am seeing messages about ...
by Jason Motivator in Getting Data In 03-21-2011
0 2
0
2
jgauthier
History: Using splunk 4.2, and added the Windows App. I noticed there are some prebuilt searches, for instance logon...
by jgauthier Contributor in Getting Data In 03-20-2011
0 4
0
4
elusive
I have Splunk monitor a log directory in /etc/log. The logs in this directory are updated and rotated. However, Spl...
by elusive Splunk Employee Splunk Employee in Getting Data In 03-18-2011
3 1
3
1
maf
Hello, I just started evaluating Splunk. So please apologize if I should ask for the obvious. My test case is a pos...
by maf New Member in Getting Data In 03-18-2011
0 3
0
3
Mountain1
Hello everybody, We have four Cisco ipsen. As described in the manual, the Cisco IPS Addon was installed. The Cisco ...
by Mountain1 New Member in Getting Data In 03-18-2011
0 1
0
1
acalvo
Scenario: I want to forward syslog data using a splunk universal forwarder. However, when it gets to the central splu...
by acalvo Explorer in Getting Data In 03-18-2011
0 3
0
3
elusive
Upgrade from 4.1.x to 4.2, when I try to start Splunk Splunkd starts but splunkweb fails with the following message: ...
by elusive Splunk Employee Splunk Employee in Getting Data In 03-18-2011
5 2
5
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...