Thread Info | |||||
---|---|---|---|---|---|
I have a file with ~6M events that gets FTP'd to Splunk on a daily basis. Unfortunately I don't have control of the o...
by
dskillman
Splunk Employee
in
Getting Data In
04-12-2010
|
1
|
1
| |||
I am using Splunk to collect data from the security logs on my network. How long does Splunk store the data that it c...
by
jsondheimer
New Member
in
Getting Data In
04-09-2010
|
0
|
2
| |||
In inputs.conf the default host name is set to the fqdn, test-server.foobar.com. But when I search for that host, it ...
by
Jaci
Splunk Employee
in
Getting Data In
04-06-2010
|
2
|
5
| |||
Hi,
I just created a new app and wanted to point my network inputs to another index, managed by my app. So, I modi...
by
rnutting24
Engager
in
Getting Data In
04-07-2010
|
1
|
3
| |||
Is there a splunk command or REST endpoint to see the tailing status of monitored files?
by
the_wolverine
Champion
in
Getting Data In
04-07-2010
|
4
|
2
| |||
Search is index="_internal" source="*metrics.log" group="queue" | timechart perc90(current_size) by name
Results a...
by
MikeyG
Explorer
in
Getting Data In
04-07-2010
|
2
|
3
| |||
I'm trying to index a file on a mapped network drive, but I keep getting seeing 'Access is denied' in splunkd.log. I ...
by
Mick
Splunk Employee
in
Getting Data In
04-07-2010
|
4
|
1
| |||
On my old setup I had all syslogs going to syslog on the Splunk server, but now I'm doing a fresh setup with Ubuntu 9...
by
rogerssoftware
Explorer
in
Getting Data In
04-06-2010
|
1
|
4
| |||
I have a bunch of Lightweight Forwarders (LWF) forwarding to my central indexer. What happens to my events when there...
by
the_wolverine
Champion
in
Getting Data In
04-06-2010
|
3
|
4
| |||
I've just upgraded to 4.1 and now I'm getting an error when I search saying:
The lookup table 'sid_lookup' does no...
by
Alan_Bradley
Path Finder
in
Getting Data In
04-06-2010
|
3
|
7
| |||
How do I go about configuring splunk forwarders running on Linux to forward to a specific index for Linux-related inf...
by
cdavidy
Explorer
in
Getting Data In
04-06-2010
|
5
|
2
| |||
If the script to roll the hotDB to the warmDB is "| debug cmd=roll index=main", would there be one for rolling the wa...
by
BunnyHop
Contributor
in
Getting Data In
03-12-2010
|
4
|
2
| |||
In my office we have a script on our log servers that monitors the hosts sending logs and alerts us if a machine star...
by
thepocketwade
Path Finder
in
Getting Data In
03-19-2010
|
0
|
4
| |||
All of my events show up with gid=-1,uid=-1. Is this a bug or am I doing something wrong?
by
oreoshake
Communicator
in
Getting Data In
03-18-2010
|
1
|
3
| |||
UPDATE: This appears to be a bug specifically related to 4.0.10. The following is a work around in system/local/input...
by
oreoshake
Communicator
in
Getting Data In
03-30-2010
|
1
|
3
| |||
I have lots of hosts in my environment, but I only want to search across a few of them from time to time. Can I someh...
by
maverick
Splunk Employee
in
Getting Data In
03-30-2010
|
1
|
2
| |||
We have an global application hosted within a VM environment feeding a common Splunk index server. However the server...
by
matt_1
Explorer
in
Getting Data In
03-29-2010
|
0
|
2
| |||
Everytime I run a splunk command on windows 7, the command runs in a separate window and closes before I can see what...
by
oreoshake
Communicator
in
Getting Data In
03-29-2010
|
1
|
2
| |||
Hai There,
I am dealing with a forwarder to indexer which is reading a kiwi directory with several types of device...
by
Starlette
Contributor
in
Getting Data In
03-28-2010
|
1
|
2
| |||
Does a sinkhole work on all types of forwarders?
by
Michael_Wilde
Splunk Employee
in
Getting Data In
03-29-2010
|
3
|
1
| |||
How to disable hostname chaining? Splunk picks the chained hostname rather than the original.
by
zliu
Splunk Employee
in
Getting Data In
03-26-2010
|
0
|
1
| |||
I have a light forwarder (v4.0.7) I want to change this to a forwarder instead of a light forwarder. The reason being...
by
Alan_Bradley
Path Finder
in
Getting Data In
03-25-2010
|
0
|
3
| |||
We're upgrading our forwarders and we always get the warning that outputs.conf cannot be migrated. However, simply mo...
by
oreoshake
Communicator
in
Getting Data In
03-19-2010
|
0
|
1
| |||
When we build 2 Splunk indexing servers for High Availablity, 2 Splunk indexing servers may receive the same log data...
by
Alan_Bradley
Path Finder
in
Getting Data In
03-19-2010
|
0
|
1
| |||
We plan to use Splunk to keep log for several java application including web server like Tomcat. Those application ar...
by
Alan_Bradley
Path Finder
in
Getting Data In
03-19-2010
|
2
|
1
|