| We are testing in a high throughput environment capturing logs that grow to 251MB in ~ 4-6 minutes at which time the ... by ericrobinson Path Finder in Getting Data In 03-16-2011 0 3 | 0 | 3 | ||
| Somehow I have a duplicate remote directory input listed in my inputs it is in the format ///servername//direcotory//... by udiggity New Member in Getting Data In 03-16-2011 0 4 | 0 | 4 | ||
| How much memory can I expect the Universal Forwarder to require on a machine? Is there a hard ceiling for the virtual... by Rob Splunk Employee 2 2 | 2 | 2 | ||
| I've just upgraded to Splunk 4.2 and have installed and started the UF on a Linux box. But when I try to run, ./splu... by Mike_McMurray Engager in Getting Data In 03-16-2011 2 3 | 2 | 3 | ||
| I have a server that had a corrupted Security Log. In order to resolve that problem I backed up the security log and... by taylorchase Engager in Getting Data In 03-16-2011 5 1 | 5 | 1 | ||
| I've noticed LWF's metrics.log were forwarded to the indexer as default in some version of splunk. But, not all the v... by Masa Splunk Employee 2 3 | 2 | 3 | ||
| I suspect that this has something to do with the fact that my log files are being generated by appending to the end ... by keycoldstorage Explorer in Getting Data In 03-15-2011 0 1 | 0 | 1 | ||
| I would like to know if there is a way to read from splunk DB and redirect that data to some other application. I hav... by sys1pmp Explorer in Getting Data In 03-14-2011 1 1 | 1 | 1 | ||
| I am using Splunk to collect logs from a diverse environment. The same events, or at least a large subset, need to b... by npatellis Explorer in Getting Data In 03-14-2011 0 1 | 0 | 1 | ||
| Hi All, Does anyone know if it's possible to take logs that have been grabbed from Windows WMI and indexed, and then... by Scarecrowddb Explorer in Getting Data In 03-14-2011 0 1 | 0 | 1 | ||
| I have installed Splunk as a forwarder/light forwarder on a few of our Win2003 x86 servers as a test and am receiving... by ccit Engager in Getting Data In 03-13-2011 0 2 | 0 | 2 | ||
| i have the lea-loggrabber.sh script working well and reliably getting all new logs from checkpoint cma into splunk. ... by EricPartington Communicator in Getting Data In 03-13-2011 0 2 | 0 | 2 | ||
| I am not very familiar with Splunk and syslog servers in general, but I am trying to learn. There is a "Broadcast on ... by Pierre Engager in Getting Data In 03-12-2011 0 3 | 0 | 3 | ||
| I recently copied the splunk-forwarder.license details mentioned in our indexer to splunk.license (into one of our fo... by heterodyned Path Finder in Getting Data In 03-10-2011 1 3 | 1 | 3 | ||
| At a few customers now I have seen a 1MB (forwarder) license with an expiration of early March. I'm not sure where th... by Jason Motivator in Getting Data In 03-10-2011 2 9 | 2 | 9 | ||
| Hi folks, I'd like to route WMI logs to different indexes based off the host name (I have a few environments) Going... by Yancy Path Finder in Getting Data In 03-10-2011 2 10 | 2 | 10 | ||
| 2011-03-09T11:21:34-04:00 ab-wtsk-mg3200-2 [Src=10.157.32.26/49842 Dst=4070 PType=6] ErrMgs=1 Cid=23: 1 RTP packets l... by Joel_Gerber Explorer in Getting Data In 03-10-2011 0 2 | 0 | 2 | ||
| Hi I've enabled the script input /opt/splunk/etc/apps/unix/bin/rlog.sh to read audit events. However I noticed ther... by remy06 Contributor in Getting Data In 03-10-2011 0 2 | 0 | 2 | ||
| I have Splunk running on a Linux server and I need to index WMI-based events, like perfmon data, from my Windows serv... by maverick Splunk Employee 0 6 | 0 | 6 | ||
| I have activity files from a vpn radius server and I'd like to label the fields as they go into splunk... I'm not eve... by udiggity New Member in Getting Data In 03-09-2011 0 2 | 0 | 2 | ||
| Our Splunk environment has multiple indexes, with role restrictions on index access. I want to allow users to upload... by cfergus Path Finder in Getting Data In 03-09-2011 0 1 | 0 | 1 | ||
| I have a perpetual Enterprise license and having not been having any issues until the today when I started to see a m... by Ellen Splunk Employee 6 2 | 6 | 2 | ||
| I have a csv tab-delimited file with entries that looks like this: GPDB20A LTO3 L03 03/08/11 06:01:20 129959288... by rasingh Path Finder in Getting Data In 03-08-2011 1 1 | 1 | 1 | ||
| I am trying to filter with many transform statements. I believe everything is configured correctly. But I get ALL e... by neusse Path Finder in Getting Data In 03-08-2011 0 3 | 0 | 3 | ||
| I only want to index the last 365 days of data. Can this be done in Splunk 4.1? Any data older than one year should b... by coryjackson New Member in Getting Data In 03-07-2011 0 2 | 0 | 2 |