| EDIT: I've discovered this only happens if I specify more than one stanza on the same port -- different remote IPs, s... by twinspop Influencer in Getting Data In 03-27-2011 0 3 | 0 | 3 | ||
| I'm trying to create a search to determine which hosts in a CSV file don't have any events associated with it within ... by zschmid Path Finder in Getting Data In 03-27-2011 2 4 | 2 | 4 | ||
| Has anyone setup the windows "netstat" command as an input? I like the "netstat" source provided in the unix app, an... by Lowell Super Champion in Getting Data In 03-26-2011 1 3 | 1 | 3 | ||
| We performed renames on several servers and am seeing them all show with a weird issue. It seems that there are still... by dchristilaw New Member in Getting Data In 03-26-2011 0 1 | 0 | 1 | ||
| I have set up a few heavy forwarders. I did this to filter data, and learn how. Some of these are on a WAN and will... by jgauthier Contributor in Getting Data In 03-26-2011 1 6 | 1 | 6 | ||
| Can I use the universal forwarder 4.2 to send data to an indexer running Splunk 4.1.7 (or older) ? by rasingh Path Finder in Getting Data In 03-25-2011 1 1 | 1 | 1 | ||
| Hi, is it possible to use different indexes on the main splunk server which received the data from windows forwarde... by krusty Contributor in Getting Data In 03-25-2011 1 8 | 1 | 8 | ||
| I have a handful of different sourcetypes that all get written to log files in /var/log/app. I also have more than o... by tpsplunk Communicator in Getting Data In 03-24-2011 3 13 | 3 | 13 | ||
| I have the following stanza in transforms.conf: [medusa_media_access-drop-events] REGEX = ^\S+\s++\S+\s++\[[^\]]*\]\... by spock_yh Path Finder in Getting Data In 03-24-2011 0 2 | 0 | 2 | ||
| I'm having a heck of a time figuring out the best way to get splunk to show these multiline events in one event. Any ... by michaelhobbs Explorer in Getting Data In 03-24-2011 1 7 | 1 | 7 | ||
| I have DNS log lines that look like the following: (4)mail(6)google(3)com(0) (7)twitter(3)com(0) (12)spreadsheets(1)... by the_wolverine Champion in Getting Data In 03-24-2011 0 5 | 0 | 5 | ||
| Hi , I have below configuration in inputs .conf [monitor:C:\Program Files\Splunk\etc\apps\sampleApp\samplelogs] I h... by spatil Path Finder in Getting Data In 03-24-2011 0 1 | 0 | 1 | ||
| Hi, as we know , before splunk eat a compressed file, splunk will decompress it first then index it. but, if we ha... by dmlee Communicator in Getting Data In 03-24-2011 1 2 | 1 | 2 | ||
| I have a Splunk 4.1.7, build 95063 instance and am trying to pull logs from Informix DB on Solaris 10. So I had set t... by splunktp Explorer in Getting Data In 03-24-2011 0 1 | 0 | 1 | ||
| Totally new with Splunk. Have mercy on my soul! I am trying to set up Splunk on my laptop as I am awaiting licens... by Rayj00 New Member in Getting Data In 03-23-2011 0 2 | 0 | 2 | ||
| Is a Splunk Agent the same as a Splunk Forwarder? Thanks, Ray by rayjsplunk New Member in Getting Data In 03-23-2011 0 3 | 0 | 3 | ||
| I tried out the option "source name override" when setting up a UDP data input to replace "UDP:514" with "mynetworkSy... by Mr_Robaloba Explorer in Getting Data In 03-23-2011 1 3 | 1 | 3 | ||
| I am trying to filter a log file coming in via a universal forwarder (both installs are 4.2) so that messages contain... by Mr_Robaloba Explorer in Getting Data In 03-23-2011 0 2 | 0 | 2 | ||
| I have a simple setup. A light forwarder, forwarder and an indexer. The light forwarder stopped working about 5 day... by DTERM Contributor in Getting Data In 03-23-2011 0 3 | 0 | 3 | ||
| Hi Splunkers, We have a macro here we're using to allow users to search their previous search history. It relies on ... by ickymettle Explorer in Getting Data In 03-23-2011 1 1 | 1 | 1 | ||
| I have about 50 forwarders in my environment. Somewhere I have screwed up, and included the same set of host data tw... by seanlon11 Path Finder in Getting Data In 03-22-2011 0 1 | 0 | 1 | ||
| We just updated to 4.2 on our splunk server, and I am in the midst of pushing the Universal Forwarder out to replace ... by bkaspar Engager in Getting Data In 03-21-2011 1 2 | 1 | 2 | ||
| Is it necessary to use si* command for summary index and we need to make it as scheduled save? Since I recall the sa... by hochit Path Finder in Getting Data In 03-21-2011 2 2 | 2 | 2 | ||
| A new type of log file has been added to an existing data input by amending the whitelist and blacklist. (new data in... by fox Path Finder in Getting Data In 03-21-2011 2 2 | 2 | 2 | ||
| I have a forwarder that appears to be a LWF (SplunkLightForwarder app is enabled) however I am seeing messages about ... by Jason Motivator in Getting Data In 03-21-2011 0 2 | 0 | 2 |