Getting Data In

Getting Data In
Community Activity
sondradotcom
Splunk is monitoring several folders, but upon careful inspection I've noticed that it seems to be "skipping" files h...
by sondradotcom Path Finder in Getting Data In 01-31-2011
1 3
1
3
apro
Hi, Like to quick check on how splunk forwarder license works... forwarder license type is displayed as Enterprise?...
by apro Path Finder in Getting Data In 01-30-2011
0 6
0
6
gfriedmann
I'm working in an environment where the light forwarders watching windows eventlog inputs are configured for many dif...
by gfriedmann Communicator in Getting Data In 01-28-2011
0 10
0
10
shahhe
Folks, I wrote perl script to run search on remote splunk server. By default the search only returns first 100 event...
by shahhe Explorer in Getting Data In 01-28-2011
1 4
1
4
mcwomble
I am trying to calculate the hardware requirements for a Splunk installation. The main issue I have is that the ha...
by mcwomble Path Finder in Getting Data In 01-27-2011
2 1
2
1
dikaye
Please see my log entries below: 1 11-1-27 下午01:40:01.000 Jan 27 13:40:01 202.XX.XX.XX postfix/qmgr[2866]: B33B...
by dikaye Path Finder in Getting Data In 01-27-2011
0 1
0
1
jbsplunk
I am monitoring a folder which contains windows event log stored in .evt/.evtx files. I would like to have this data ...
by jbsplunk Splunk Employee Splunk Employee in Getting Data In 01-26-2011
6 1
6
1
shahhe
How can I order the results by time (_time + _subsecond fields) and then by host field? Thanks.
by shahhe Explorer in Getting Data In 01-26-2011
0 6
0
6
benstraw
I have a 1GB license and I am trying to contain my daily indexing so that I don't exceed the maximum indexing volume...
by benstraw Splunk Employee Splunk Employee in Getting Data In 01-26-2011
3 3
3
3
jambajuice
I am trying to index a file that looks like the following: 1,"Location" 2,"Attack Type" 3,"Impact" 4,"Exploit" 5,"OS...
by jambajuice Communicator in Getting Data In 01-26-2011
1 3
1
3
jambajuice
I have results that look like the following dest_ip, dest_port, protocol, cve_id, score 192.168.1.1, 80, tcp, 200...
by jambajuice Communicator in Getting Data In 01-25-2011
1 1
1
1
clyde772
I had instances where many of my forwaders filled up disk partition to go full. How can I disable all logging? Ofco...
by clyde772 Communicator in Getting Data In 01-25-2011
0 1
0
1
stuartamurray
We've got a fairly chunky installation and generally things hum along nicely. However sometimes I get a situation wh...
by stuartamurray Path Finder in Getting Data In 01-25-2011
0 3
0
3
jcbrendsel
We have a forwarder/receiver topology configured here. Each of the 200 or so servers have a light forwarder their in...
by jcbrendsel Path Finder in Getting Data In 01-22-2011
0 1
0
1
cppforlife
Hello, I have a big log file that is set to be sourcetype=my_log and it basically looks like this: --- begin_request...
by cppforlife New Member in Getting Data In 01-21-2011
0 2
0
2
ruiaires
I have a Splunk server that receives data from 2 normal (not light) forwarders. In the forwarders, I had to create a...
by ruiaires Path Finder in Getting Data In 01-21-2011
1 2
1
2
Christian
Hi all, i know there are a few other questions with good answers about my topic but I still have my problems. This ...
by Christian Path Finder in Getting Data In 01-21-2011
1 2
1
2
ndoshi
On 64 bit Windows, if the download is correct (64 bit), the user is running as Administrator, Splunk is installed as ...
by ndoshi Splunk Employee Splunk Employee in Getting Data In 01-21-2011
0 10
0
10
tgiles
Hi, All. Is there a way to send a unique system ID from a forwarder to a Splunk indexer along with the logs? I hav...
by tgiles Path Finder in Getting Data In 01-20-2011
0 4
0
4
mctester
I'm running version 4.0.8 splunk on Windows 2000 and it continually generates the following error. Application popu...
by mctester Communicator in Getting Data In 01-20-2011
0 4
0
4
CPMSupport
Hi I've recently installed Splunk and have set up a couple of our test ESX host to forward syslog data to the Splunk ...
by CPMSupport Engager in Getting Data In 01-20-2011
2 3
2
3
vivsplunk
I'm trying to use "Monitor Files & Directories" as data input. I got two Data Input sources, One is script that runs...
by vivsplunk Engager in Getting Data In 01-19-2011
1 3
1
3
balbano
Is there someway to setup 1 TCP or UDP listening port and have it direct logs to more than one index depending on whi...
by balbano Contributor in Getting Data In 01-19-2011
2 6
2
6
cmeo
I have a source which is csv but has no headers. I'm trying to set up props.conf and transforms.conf to supply these ...
by cmeo Contributor in Getting Data In 01-19-2011
1 6
1
6
Voltaire
Is it possible to monitor a log file from a Linux system that is not configured as a LWF? I configured the Data Inp...
by Voltaire Communicator in Getting Data In 01-18-2011
0 4
0
4
Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...
Top Solution Authors