| Thread Info | |||||
|---|---|---|---|---|---|
|
I'm in a Windows environment, trying to set up forwarding to my indexer, all on Windows 2008 servers.
So, I made s...
by
gsawyer1
Engager
in
Getting Data In
08-31-2010
|
0
|
5
| |||
|
I’m currently running Splunk on my Windows XP SP3 and I'm trying to get a couple scripts to run after an alert trigge...
by
maverick
Splunk Employee
in
Getting Data In
08-31-2010
|
3
|
4
| |||
|
Hi all, Basically for example's sake; lets say i have 45 web server clients logging to a Splunk Indexer and it is the...
by
dalgibbard
Engager
in
Getting Data In
08-31-2010
|
0
|
5
| |||
|
I am running Splunk on Windows 7 64 bit and configured data adapters for syslog on TCP and UDP. I can see via Wiresha...
by
local_graph_2
New Member
in
Getting Data In
08-22-2010
|
0
|
6
| |||
|
I want to get logs and data from my sidewinder firewall running 7.0.0.06. How do I do it?
by
wrightp
New Member
in
Getting Data In
08-17-2010
|
0
|
2
| |||
|
I installed Splunk on my Windows XP machine and I'm trying to setup the "Source" to "Monitor a file or directory" whi...
by
jerry_john
Engager
in
Getting Data In
08-18-2010
|
1
|
2
| |||
|
All of a sudden my 4.0.9 Splunk server is no longer forwarding the WinEventLog:Security logs onto my 4.1.4 Linux inde...
by
Ellen
Splunk Employee
in
Getting Data In
09-01-2010
|
2
|
1
| |||
|
I am trying batch upload like this from a light forwarder. But the files are not being consumed (there are only 2 sma...
by
skattamu
New Member
in
Getting Data In
08-10-2010
|
0
|
5
| |||
|
I have a long list of hosts/sources/sourcetypes I want to restrict a user to. Can I define a macro, then reference th...
by
hulahoop
Splunk Employee
in
Getting Data In
08-30-2010
|
1
|
6
| |||
|
Hi,
Is there a way to have this search do following: get me all sources that related to windows (win*) - then calc...
by
DyJohnnY
Explorer
in
Getting Data In
08-30-2010
|
0
|
2
| |||
|
I know that Splunk can parse all different types of timestamps, but I've got a funky one. Here's the situation:
AI...
by
Branden
Builder
in
Getting Data In
08-31-2010
|
1
|
6
| |||
|
Hi,
My instance of Splunk is monitoring a server log file that is updated at periods throughout the day. Splunk ha...
by
Ant1D
Motivator
in
Getting Data In
08-31-2010
|
0
|
5
| |||
|
I would like to know wether it is possible to filter remote windows eventlog based on the groups inside wmi.conf. I h...
by
Daniel
Explorer
in
Getting Data In
08-30-2010
|
0
|
6
| |||
|
We have a monitoring system (WhatsUpGold) that periodically logs in to our windows machines and checks various condit...
by
Lowell
Super Champion
in
Getting Data In
08-28-2010
|
1
|
2
| |||
|
Is there a way to see what files are being read by the various monitor/fschange stanzas in input.conf?
by
drawks
Explorer
in
Getting Data In
08-30-2010
|
2
|
2
| |||
|
Receiving splunk server inputs.conf:
[splunktcp://7900]
Sending splunk server outputs.conf:
[tcpout]
defaul...
by
twinspop
Influencer
in
Getting Data In
08-17-2010
|
0
|
11
| |||
|
Is there a way to extract the hostname from an event, but force it to lower-case in the process?
Extracting the ho...
by
southeringtonp
Motivator
in
Getting Data In
08-27-2010
|
6
|
2
| |||
|
The operating system won't allow a non-root user to bind to ports < 1024. How can I get my splunkd, running as user s...
by
dwaddle
SplunkTrust
in
Getting Data In
08-27-2010
|
11
|
2
| |||
|
Hello, I have a chart that show event counts split by source name. For our analysis, it is very important that we see...
by
ericrobinson
Path Finder
in
Getting Data In
08-27-2010
|
2
|
2
| |||
|
for each [WinEventLog: ] stanza in inputs.conf, can you specify more than one entry for evt_dc_name? Because what if ...
by
gsawyer1
Engager
in
Getting Data In
08-26-2010
|
0
|
1
| |||
|
I was wondering if it were possible to do a mask on events in addition to sending them to a separate index.
Since ...
by
caphrim007
Path Finder
in
Getting Data In
08-25-2010
|
0
|
2
| |||
|
I have a bunch of light forwarders sending data to a central heavy forwarder which sends the data to the main indexer...
by
aaronzabell
Path Finder
in
Getting Data In
08-18-2010
|
0
|
7
| |||
|
Is there a way with the basic Forwarder to configure it to send events to server A if its up, and to server B only if...
by
dnolan
Explorer
in
Getting Data In
08-19-2010
|
1
|
4
| |||
|
Hi
To update our splunk forwarders we use puppet. Puppet first removes the splunk package and then installs the n...
by
chris
Motivator
in
Getting Data In
08-24-2010
|
0
|
3
| |||
|
Hi,
I have a forwarder sending a syslog file to the receiver. The syslog has entries like:
Jul 27 09:50:21 ip-...
by
sunnykkim
Engager
in
Getting Data In
07-27-2010
|
1
|
3
|