Getting Data In

Getting Data In
Community Activity
ericrobinson
We are testing in a high throughput environment capturing logs that grow to 251MB in ~ 4-6 minutes at which time the ...
by ericrobinson Path Finder in Getting Data In 03-16-2011
0 3
0
3
udiggity
Somehow I have a duplicate remote directory input listed in my inputs it is in the format ///servername//direcotory//...
by udiggity New Member in Getting Data In 03-16-2011
0 4
0
4
Rob
How much memory can I expect the Universal Forwarder to require on a machine? Is there a hard ceiling for the virtual...
by Rob Splunk Employee Splunk Employee in Getting Data In 03-16-2011
2 2
2
2
Mike_McMurray
I've just upgraded to Splunk 4.2 and have installed and started the UF on a Linux box. But when I try to run, ./splu...
by Mike_McMurray Engager in Getting Data In 03-16-2011
2 3
2
3
taylorchase
I have a server that had a corrupted Security Log. In order to resolve that problem I backed up the security log and...
by taylorchase Engager in Getting Data In 03-16-2011
5 1
5
1
Masa
I've noticed LWF's metrics.log were forwarded to the indexer as default in some version of splunk. But, not all the v...
by Masa Splunk Employee Splunk Employee in Getting Data In 03-15-2011
2 3
2
3
keycoldstorage
I suspect that this has something to do with the fact that my log files are being generated by appending to the end ...
by keycoldstorage Explorer in Getting Data In 03-15-2011
0 1
0
1
sys1pmp
I would like to know if there is a way to read from splunk DB and redirect that data to some other application. I hav...
by sys1pmp Explorer in Getting Data In 03-14-2011
1 1
1
1
npatellis
I am using Splunk to collect logs from a diverse environment. The same events, or at least a large subset, need to b...
by npatellis Explorer in Getting Data In 03-14-2011
0 1
0
1
Scarecrowddb
Hi All, Does anyone know if it's possible to take logs that have been grabbed from Windows WMI and indexed, and then...
by Scarecrowddb Explorer in Getting Data In 03-14-2011
0 1
0
1
ccit
I have installed Splunk as a forwarder/light forwarder on a few of our Win2003 x86 servers as a test and am receiving...
by ccit Engager in Getting Data In 03-13-2011
0 2
0
2
EricPartington
i have the lea-loggrabber.sh script working well and reliably getting all new logs from checkpoint cma into splunk. ...
by EricPartington Communicator in Getting Data In 03-13-2011
0 2
0
2
Pierre
I am not very familiar with Splunk and syslog servers in general, but I am trying to learn. There is a "Broadcast on ...
by Pierre Engager in Getting Data In 03-12-2011
0 3
0
3
heterodyned
I recently copied the splunk-forwarder.license details mentioned in our indexer to splunk.license (into one of our fo...
by heterodyned Path Finder in Getting Data In 03-10-2011
1 3
1
3
Jason
At a few customers now I have seen a 1MB (forwarder) license with an expiration of early March. I'm not sure where th...
by Jason Motivator in Getting Data In 03-10-2011
2 9
2
9
Yancy
Hi folks, I'd like to route WMI logs to different indexes based off the host name (I have a few environments) Going...
by Yancy Path Finder in Getting Data In 03-10-2011
2 10
2
10
Joel_Gerber
2011-03-09T11:21:34-04:00 ab-wtsk-mg3200-2 [Src=10.157.32.26/49842 Dst=4070 PType=6] ErrMgs=1 Cid=23: 1 RTP packets l...
by Joel_Gerber Explorer in Getting Data In 03-10-2011
0 2
0
2
remy06
Hi I've enabled the script input /opt/splunk/etc/apps/unix/bin/rlog.sh to read audit events. However I noticed ther...
by remy06 Contributor in Getting Data In 03-10-2011
0 2
0
2
maverick
I have Splunk running on a Linux server and I need to index WMI-based events, like perfmon data, from my Windows serv...
by maverick Splunk Employee Splunk Employee in Getting Data In 03-09-2011
0 6
0
6
udiggity
I have activity files from a vpn radius server and I'd like to label the fields as they go into splunk... I'm not eve...
by udiggity New Member in Getting Data In 03-09-2011
0 2
0
2
cfergus
Our Splunk environment has multiple indexes, with role restrictions on index access. I want to allow users to upload...
by cfergus Path Finder in Getting Data In 03-09-2011
0 1
0
1
Ellen
I have a perpetual Enterprise license and having not been having any issues until the today when I started to see a m...
by Ellen Splunk Employee Splunk Employee in Getting Data In 03-09-2011
6 2
6
2
rasingh
I have a csv tab-delimited file with entries that looks like this: GPDB20A LTO3 L03 03/08/11 06:01:20 129959288...
by rasingh Path Finder in Getting Data In 03-08-2011
1 1
1
1
neusse
I am trying to filter with many transform statements. I believe everything is configured correctly. But I get ALL e...
by neusse Path Finder in Getting Data In 03-08-2011
0 3
0
3
coryjackson
I only want to index the last 365 days of data. Can this be done in Splunk 4.1? Any data older than one year should b...
by coryjackson New Member in Getting Data In 03-07-2011
0 2
0
2
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors