| At a few customers now I have seen a 1MB (forwarder) license with an expiration of early March. I'm not sure where th... by Jason Motivator in Getting Data In 03-10-2011 2 9 | 2 | 9 | ||
| Hi folks, I'd like to route WMI logs to different indexes based off the host name (I have a few environments) Going... by Yancy Path Finder in Getting Data In 03-10-2011 2 10 | 2 | 10 | ||
| 2011-03-09T11:21:34-04:00 ab-wtsk-mg3200-2 [Src=10.157.32.26/49842 Dst=4070 PType=6] ErrMgs=1 Cid=23: 1 RTP packets l... by Joel_Gerber Explorer in Getting Data In 03-10-2011 0 2 | 0 | 2 | ||
| Hi I've enabled the script input /opt/splunk/etc/apps/unix/bin/rlog.sh to read audit events. However I noticed ther... by remy06 Contributor in Getting Data In 03-10-2011 0 2 | 0 | 2 | ||
| I have Splunk running on a Linux server and I need to index WMI-based events, like perfmon data, from my Windows serv... by maverick Splunk Employee 0 6 | 0 | 6 | ||
| I have activity files from a vpn radius server and I'd like to label the fields as they go into splunk... I'm not eve... by udiggity New Member in Getting Data In 03-09-2011 0 2 | 0 | 2 | ||
| Our Splunk environment has multiple indexes, with role restrictions on index access. I want to allow users to upload... by cfergus Path Finder in Getting Data In 03-09-2011 0 1 | 0 | 1 | ||
| I have a perpetual Enterprise license and having not been having any issues until the today when I started to see a m... by Ellen Splunk Employee 6 2 | 6 | 2 | ||
| I have a csv tab-delimited file with entries that looks like this: GPDB20A LTO3 L03 03/08/11 06:01:20 129959288... by rasingh Path Finder in Getting Data In 03-08-2011 1 1 | 1 | 1 | ||
| I am trying to filter with many transform statements. I believe everything is configured correctly. But I get ALL e... by neusse Path Finder in Getting Data In 03-08-2011 0 3 | 0 | 3 | ||
| I only want to index the last 365 days of data. Can this be done in Splunk 4.1? Any data older than one year should b... by coryjackson New Member in Getting Data In 03-07-2011 0 2 | 0 | 2 | ||
| I have one Splunk receiver set up and several forwarders (forwarders using free version). About 9 of my hosts are li... by lmalhoit Explorer in Getting Data In 03-07-2011 0 4 | 0 | 4 | ||
| Has anybody dealt with splunking Windows Robocopy.exe logs? I'm about to dive into it, and am looking for prior art.... by anewell Path Finder in Getting Data In 03-06-2011 0 1 | 0 | 1 | ||
| Hello folks, I'm trying to puzzle out getting around SPL-34965 (WMI not load balancing), not inundating a single ind... by hacktastic Path Finder in Getting Data In 03-04-2011 0 1 | 0 | 1 | ||
| I'm indexing a CSV file and I just can't get Splunk to extract any fields or apply the proper sourcetype to the event... by erga00 Path Finder in Getting Data In 03-04-2011 3 7 | 3 | 7 | ||
| Hello, I am trying to pick up to files in specific directories under different sourectypes. [monitor:///app/ems-s... by Hazel Communicator in Getting Data In 03-04-2011 0 10 | 0 | 10 | ||
| We want to write an program to gather logging information from our HP NonStop system log files, both OSS and Guardian... by ticsoftware New Member in Getting Data In 03-04-2011 0 2 | 0 | 2 | ||
| Hi, I have a sourcetype where i defined the field names in the transforms.conf Transforms.conf [my_parse] DELIMS ... by cramasta Builder in Getting Data In 03-03-2011 0 4 | 0 | 4 | ||
| Hi, How can I delete old hosts from web interface (all indexed data) in search window? Thanks in advance by mudricd Explorer in Getting Data In 03-02-2011 2 4 | 2 | 4 | ||
| I have some firewalls and stuff like that send logs to my Splunk server (using normal syslog at the moment). For now ... by fisk12 Path Finder in Getting Data In 03-02-2011 1 3 | 1 | 3 | ||
| How can I proactively monitor my Splunk indexes to make sure they are still indexing? I have an SNMP monitoring appl... by gharpe2 Explorer in Getting Data In 03-02-2011 1 1 | 1 | 1 | ||
| Hello Im looking to do some stats on the traffic to my companys webserver (apache). Im using splunk as a lightforward... by fisk12 Path Finder in Getting Data In 03-01-2011 0 5 | 0 | 5 | ||
| Is there anyway to ignore the events time stamp, and set it to the current system time (at the event's index time)? ... by carmackd Communicator in Getting Data In 03-01-2011 2 5 | 2 | 5 | ||
| I have UDP 514 input data configured for syslog but somehow if i select sourcetype From list : syslog and save it a... by satishp Explorer in Getting Data In 03-01-2011 0 1 | 0 | 1 | ||
| Hi I'm new to Splunk and the tools looks very interesting - Currently Evaluating to replace ORiON SolarWinds APM. Ho... by staces65 Engager in Getting Data In 03-01-2011 2 2 | 2 | 2 |