| Hi, is it possible to use different indexes on the main splunk server which received the data from windows forwarde... by krusty Contributor in Getting Data In 03-25-2011 1 8 | 1 | 8 | ||
| I have a handful of different sourcetypes that all get written to log files in /var/log/app. I also have more than o... by tpsplunk Communicator in Getting Data In 03-24-2011 3 13 | 3 | 13 | ||
| I have the following stanza in transforms.conf: [medusa_media_access-drop-events] REGEX = ^\S+\s++\S+\s++\[[^\]]*\]\... by spock_yh Path Finder in Getting Data In 03-24-2011 0 2 | 0 | 2 | ||
| I'm having a heck of a time figuring out the best way to get splunk to show these multiline events in one event. Any ... by michaelhobbs Explorer in Getting Data In 03-24-2011 1 7 | 1 | 7 | ||
| I have DNS log lines that look like the following: (4)mail(6)google(3)com(0) (7)twitter(3)com(0) (12)spreadsheets(1)... by the_wolverine Champion in Getting Data In 03-24-2011 0 5 | 0 | 5 | ||
| Hi , I have below configuration in inputs .conf [monitor:C:\Program Files\Splunk\etc\apps\sampleApp\samplelogs] I h... by spatil Path Finder in Getting Data In 03-24-2011 0 1 | 0 | 1 | ||
| Hi, as we know , before splunk eat a compressed file, splunk will decompress it first then index it. but, if we ha... by dmlee Communicator in Getting Data In 03-24-2011 1 2 | 1 | 2 | ||
| I have a Splunk 4.1.7, build 95063 instance and am trying to pull logs from Informix DB on Solaris 10. So I had set t... by splunktp Explorer in Getting Data In 03-24-2011 0 1 | 0 | 1 | ||
| Totally new with Splunk. Have mercy on my soul! I am trying to set up Splunk on my laptop as I am awaiting licens... by Rayj00 New Member in Getting Data In 03-23-2011 0 2 | 0 | 2 | ||
| Is a Splunk Agent the same as a Splunk Forwarder? Thanks, Ray by rayjsplunk New Member in Getting Data In 03-23-2011 0 3 | 0 | 3 | ||
| I tried out the option "source name override" when setting up a UDP data input to replace "UDP:514" with "mynetworkSy... by Mr_Robaloba Explorer in Getting Data In 03-23-2011 1 3 | 1 | 3 | ||
| I am trying to filter a log file coming in via a universal forwarder (both installs are 4.2) so that messages contain... by Mr_Robaloba Explorer in Getting Data In 03-23-2011 0 2 | 0 | 2 | ||
| I have a simple setup. A light forwarder, forwarder and an indexer. The light forwarder stopped working about 5 day... by DTERM Contributor in Getting Data In 03-23-2011 0 3 | 0 | 3 | ||
| Hi Splunkers, We have a macro here we're using to allow users to search their previous search history. It relies on ... by ickymettle Explorer in Getting Data In 03-23-2011 1 1 | 1 | 1 | ||
| I have about 50 forwarders in my environment. Somewhere I have screwed up, and included the same set of host data tw... by seanlon11 Path Finder in Getting Data In 03-22-2011 0 1 | 0 | 1 | ||
| We just updated to 4.2 on our splunk server, and I am in the midst of pushing the Universal Forwarder out to replace ... by bkaspar Engager in Getting Data In 03-21-2011 1 2 | 1 | 2 | ||
| Is it necessary to use si* command for summary index and we need to make it as scheduled save? Since I recall the sa... by hochit Path Finder in Getting Data In 03-21-2011 2 2 | 2 | 2 | ||
| A new type of log file has been added to an existing data input by amending the whitelist and blacklist. (new data in... by fox Path Finder in Getting Data In 03-21-2011 2 2 | 2 | 2 | ||
| I have a forwarder that appears to be a LWF (SplunkLightForwarder app is enabled) however I am seeing messages about ... by Jason Motivator in Getting Data In 03-21-2011 0 2 | 0 | 2 | ||
| History: Using splunk 4.2, and added the Windows App. I noticed there are some prebuilt searches, for instance logon... by jgauthier Contributor in Getting Data In 03-20-2011 0 4 | 0 | 4 | ||
| I have Splunk monitor a log directory in /etc/log. The logs in this directory are updated and rotated. However, Spl... by elusive Splunk Employee 3 1 | 3 | 1 | ||
| Hello, I just started evaluating Splunk. So please apologize if I should ask for the obvious. My test case is a pos... by maf New Member in Getting Data In 03-18-2011 0 3 | 0 | 3 | ||
| Hello everybody, We have four Cisco ipsen. As described in the manual, the Cisco IPS Addon was installed. The Cisco ... by Mountain1 New Member in Getting Data In 03-18-2011 0 1 | 0 | 1 | ||
| Scenario: I want to forward syslog data using a splunk universal forwarder. However, when it gets to the central splu... by acalvo Explorer in Getting Data In 03-18-2011 0 3 | 0 | 3 | ||
| Upgrade from 4.1.x to 4.2, when I try to start Splunk Splunkd starts but splunkweb fails with the following message: ... by elusive Splunk Employee 5 2 | 5 | 2 |