Getting Data In

Getting Data In
Community Activity
mikelanghorst
After installing Splunk on a new node as a LightWeightForwarder and configuring for the local logs I wanted to monito...
by mikelanghorst Motivator in Getting Data In 11-24-2010
3 1
3
1
wildbill4
New to Splunk.... Was in the role section and deleted the User role and now I am getting the error "Authorization Fai...
by wildbill4 Path Finder in Getting Data In 11-24-2010
2 6
2
6
rwssoccer1
Maybe you can help me out with something. I have multiple files of the same type, error_log files, that are named dif...
by rwssoccer1 New Member in Getting Data In 11-23-2010
0 2
0
2
tawollen
I have a few issues when trying to use fschange. even though fullEvent = true & sendEventMaxSize = -1, I am still ge...
by tawollen Path Finder in Getting Data In 11-23-2010
0 3
0
3
maverick
For the purposes of PCI compliance, has anyone figured out how to monitor changes/queries (containing user CC info) m...
by maverick Splunk Employee Splunk Employee in Getting Data In 11-22-2010
0 1
0
1
bjbush1
There seems to be a 10 to 15 minute delay in the data that is being sent from a light weight forwarder to my central ...
by bjbush1 Engager in Getting Data In 11-22-2010
2 3
2
3
joonradley
I am using fschange to monitor some gziped files. When the full event is loaded it is index as binary gzip and not ...
by joonradley Path Finder in Getting Data In 11-19-2010
1 1
1
1
sideview
Im curious if anyone has any advice, cautionary tales, or good examples about how to go about indexing data from a da...
by SplunkTrust SplunkTrust in Getting Data In 11-18-2010
0 1
0
1
elusive
Splunk was collecting event before but suddenly it stopped collecting events. I have restarted Splunk several times....
by elusive Splunk Employee Splunk Employee in Getting Data In 11-18-2010
3 1
3
1
EricPartington
I am having difficulty getting linebreaking working for a particular type of syslog messages. I have looked at http:...
by EricPartington Communicator in Getting Data In 11-18-2010
0 12
0
12
sjloh17
Greetings! I am trying to merge 2 lines into 1 event but having problems. Appreciate advice on my steps taken Sampl...
by sjloh17 Explorer in Getting Data In 11-18-2010
1 5
1
5
Kendrick33
I want add some files from a directory to be monitored by splunk, but I also want to give it a new sourcetype called ...
by Kendrick33 Explorer in Getting Data In 11-17-2010
0 2
0
2
scalexan62
I would like to monitor a subversion repository for changes. Is this something I can do with Splunk?
by scalexan62 Engager in Getting Data In 11-17-2010
1 2
1
2
rroberts
Is there a way to make Light Forwarder include the name of the file it is sending events from (i.e. source) when send...
by rroberts Splunk Employee Splunk Employee in Getting Data In 11-17-2010
0 3
0
3
Paolo_Prigione
Hi everybody, is it possible to teach a custom datetime.xml that my subsecond field is only two digit long? I have ...
by Paolo_Prigione Builder in Getting Data In 11-17-2010
0 4
0
4
vadud3
According to my Deployment monitor app one of my indexer shows backed up. I need help find out if it is some thing du...
by vadud3 Path Finder in Getting Data In 11-17-2010
0 8
0
8
Alexandre_Nizou
Hi everyone. Quite new to the product, I am struggling a bit. All my logs are coming through syslog on TCP 514 and I...
by Alexandre_Nizou Explorer in Getting Data In 11-17-2010
1 9
1
9
stockwel
Hi, Trying to send all eventIDs from WinEventLog:Security to NullQueue with the exception of 592 and 593. Still get...
by stockwel Engager in Getting Data In 11-16-2010
2 4
2
4
Jason
I have a very talkative data source that I only want a few fields - not entire events - from. How do I keep the parts...
by Jason Motivator in Getting Data In 11-16-2010
0 3
0
3
lrhazi
Can I say this? [source::/usr/local/blackboard/*] TRANSFORMS-routing=otherRouting In my inputs, I have pretty long...
by lrhazi Path Finder in Getting Data In 11-16-2010
0 1
0
1
melipla
Somehow I've managed to get three different sourcetypes for syslog appearing in my search results: "syslog" 2,049,49...
by melipla Explorer in Getting Data In 11-16-2010
1 5
1
5
Ant1D
Hey, I have a Titlebar module in my form with the following code: <module name="TitleBar" layoutPanel="viewHea...
by Ant1D Motivator in Getting Data In 11-16-2010
0 3
0
3
igoforth
I have a Win7 PC on which I would like to run splunk, but the majority of machines (mostly UNIX) I would like to moni...
by igoforth New Member in Getting Data In 11-16-2010
0 3
0
3
jslocomb
I am attempting to index a apache logs directory. We use cronolog to split our apache log files We have a sub direc...
by jslocomb New Member in Getting Data In 11-15-2010
0 3
0
3
andiih
I'm trying to configure splunk to collect system and security logs via WMI from workstations. I don't know who is at ...
by andiih Explorer in Getting Data In 11-15-2010
1 4
1
4
Get Updates on the Splunk Community!

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...
Top Solution Authors