Getting Data In

Getting Data In
Community Activity
manuarora
Hi, I have following inputs.conf [script://$SPLUNK_HOME/etc/apps/appa/bin/script1.sh] index = index1 sourcetype = s...
by manuarora Explorer in Getting Data In 04-20-2011
0 4
0
4
Branden
I noticed support for AIX 6.1 as of Splunk 4.2. Great! Then I noticed support for AIX 6.1 taken away with Splunk 4....
by Branden Builder in Getting Data In 04-20-2011
0 2
0
2
travispowell
I read a post on the site describing how an optimum custom log format for Splunk would take the form: <timestamp> ke...
by travispowell Path Finder in Getting Data In 04-19-2011
0 3
0
3
vbumgarner
I believe that if a directory mentioned in a monitor statement is not there when splunk starts up, the directory will...
by vbumgarner Contributor in Getting Data In 04-19-2011
0 1
0
1
trevorford
If I have a 4.2 Universal Forwarder (Windows) installed on a machine that was migrated from 4.1.x and still has the o...
by trevorford New Member in Getting Data In 04-19-2011
0 1
0
1
willthames
My props.conf has: [server] MAX_TIMESTAMP_LOOKAHEAD = 0 SHOULD_LINEMERGE = true #BREAK_ONLY_BEFORE_DATE = true BREAK...
by willthames Path Finder in Getting Data In 04-19-2011
2 7
2
7
Starlette
I have a single source and my main config is based on overided sourcetypes. So is it save to build all configs (FIELD...
by Starlette Contributor in Getting Data In 04-18-2011
0 2
0
2
oscargarcia
Hi, We are indexing a substantial number of XML files. These files have between 30% and 50% of white space that can ...
by oscargarcia Path Finder in Getting Data In 04-15-2011
0 4
0
4
bmayer00
I have the following confs inputs: [monitor:///opt/logs/\*.prd/\*/\*EndAudit.csv] disable = false index = foo pro...
by bmayer00 Engager in Getting Data In 04-15-2011
0 1
0
1
MasterOogway
I am attempting to bring data together from servers sitting in GMT in line with the logs from servers sitting in CMT,...
by MasterOogway Communicator in Getting Data In 04-15-2011
1 3
1
3
brianm1002
I have one splunk indexer that receives data from a variety of hosts. I want to also forward the data coming in from ...
by brianm1002 New Member in Getting Data In 04-15-2011
0 1
0
1
oscargarcia
Hi, We have a system with many indexed small xml files. Is it possible to have a link/view that displays the full co...
by oscargarcia Path Finder in Getting Data In 04-15-2011
0 2
0
2
shanleyj
Hi I'm forwarding logs into Splunk from a database trace file via monitor through a LWF. Example file content is a...
by shanleyj Explorer in Getting Data In 04-15-2011
0 2
0
2
David
I need to figure out how I can gracefully revise data that's already been indexed. My use case is this: We are monit...
by David Splunk Employee Splunk Employee in Getting Data In 04-14-2011
1 2
1
2
suhprano
Can Splunk universal forwarders handle and forward newly created log files? I would like to forward data as raw logs ...
by suhprano Path Finder in Getting Data In 04-14-2011
2 1
2
1
brandnew_users
I think i'm going mad. I'm a brand new user who's eval-ing splunk, seems powerful but i'd like to get all my logs in...
by brandnew_users Explorer in Getting Data In 04-14-2011
0 3
0
3
charlesm
I know there are similar questions, but not exactly and the answers don't seem to apply. Also, I'm a noob so forgive...
by charlesm Explorer in Getting Data In 04-14-2011
0 3
0
3
mamaral
I need to figure mine collection of universal forwarders to sent information to distinct tcp ports... Basicaly: ...
by mamaral Path Finder in Getting Data In 04-14-2011
0 2
0
2
mdumka
Hello, I am very new to Splunk. I have got it up and running on a Linux Box and analyzing some IIS logs and everythi...
by mdumka Engager in Getting Data In 04-13-2011
1 2
1
2
RicoSuave
Hello. I'm having an issue when indexing a csv file. The format of the data is like this. Employee,Date,Dept,Hours,H...
by RicoSuave Builder in Getting Data In 04-13-2011
0 5
0
5
terryblair
I had splunk running on a windows machine with my cisco asa 5505 sending syslogs too it and I was able to see destina...
by terryblair New Member in Getting Data In 04-13-2011
0 1
0
1
mburbidg
I'm trying to filter some events on an indexer that I'm not interested in. I have a single indexer/search node and th...
by mburbidg Explorer in Getting Data In 04-13-2011
0 2
0
2
tkropp
Not working...... I'm testing field extractions on some new logs. I created simple regex to extract server names fr...
by tkropp Path Finder in Getting Data In 04-13-2011
0 2
0
2
brianm1002
I have one Splunk indexer that both indexes and forwards the data to a second Splunk indexer. The name of the index ...
by brianm1002 New Member in Getting Data In 04-13-2011
0 3
0
3
Scott
I have a VoIP telephony server and I'm hesitant to place a splunk light forwarder on this server at this time (CR won...
by Scott Engager in Getting Data In 04-13-2011
0 7
0
7
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...
Top Solution Authors