Getting Data In

Getting Data In
Community Activity
remy06
I have about 8 files of the same kind of event logs which I require Splunk to index. Splunk managed to index 6 of the...
by remy06 Contributor in Getting Data In 10-01-2010
3 1
3
1
ultra
Before I ask my question, this is my environment. 1 forwarder 4 indexers 1 search head I am trying to setup sever...
by ultra Explorer in Getting Data In 09-30-2010
0 3
0
3
Derek
Hi, Is there a search that can return the list of indexes configured on a Splunk Indexer? Or is the only way to loo...
by Derek Path Finder in Getting Data In 09-30-2010
0 2
0
2
carmackd
Can I use more than one DEST_KEY? For example DEST_KEY=_MetaData:Index,MetaData:Sourcetype FORMAT=sourcetype::VPN,i...
by carmackd Communicator in Getting Data In 09-29-2010
0 1
0
1
twinspop
I'm using the forwarder license on my search head. I've disabled all inputs, and any extra apps. Yet I still get lice...
by twinspop Influencer in Getting Data In 09-29-2010
0 2
0
2
rsigle
I have a script that outputs between 300 and 800 lines. The output seems to be truncated after 138 lines. Is there ...
by rsigle Explorer in Getting Data In 09-28-2010
0 3
0
3
imrago
Hi, I am unable to extract a valid _time from the following log: 0168 004 07:59:03 09:01:35 0062 asdfghj ee bonfany...
by imrago Contributor in Getting Data In 09-27-2010
0 10
0
10
pmr
I'm unable to force sourcetype from props.conf. Relatively new to splunk, am trying to setup logging of solaris /var...
by pmr Explorer in Getting Data In 09-27-2010
0 2
0
2
briang67
We have a log file which contains a 7 digit second timestamp like the below: 08:30:00.2124216 We periodically need t...
by briang67 Communicator in Getting Data In 09-25-2010
1 2
1
2
dveith
Please advise. Linux Splunk Server 4.1.5 Light forwarder is installed on Windows IIS web Servers Trying to get W3C ...
by dveith Explorer in Getting Data In 09-24-2010
2 7
2
7
rasingh
I am trying to extract the fields from the AIX command fcstat so I can grap SAN HBA statistics. The output of the com...
by rasingh Path Finder in Getting Data In 09-24-2010
0 1
0
1
Genti
Log is similar to this but with many more lines: Tue Sep 21 00:01:07 MDT 2010 No filename specified, using '*'. Tue ...
by Genti Splunk Employee Splunk Employee in Getting Data In 09-24-2010
0 7
0
7
maverick
Does anyone have a sample alert script that, once triggered, takes the data set handle passed to it from the Splunk a...
by maverick Splunk Employee Splunk Employee in Getting Data In 09-24-2010
0 1
0
1
elusive
There are a lot of these error messages logged in splunkd.log 09-23-2010 09:31:28.062 ERROR WinEventLogChannel - sub...
by elusive Splunk Employee Splunk Employee in Getting Data In 09-23-2010
1 1
1
1
mbrunetto
I'm receiving many errors (to the tune of 20GB/day from one server) in my _internal from a light forwarder. Target: ...
by mbrunetto Path Finder in Getting Data In 09-23-2010
0 3
0
3
amra
Splunk stopped following data input files for changes. This happend after I was accessing https://splunk-server:8089/...
by amra Engager in Getting Data In 09-23-2010
1 4
1
4
Chris_R_
I have two indexers and a (various#) number of forwarders, how can i use SSL for all traffic between these boxes?
by Chris_R_ Splunk Employee Splunk Employee in Getting Data In 09-23-2010
0 2
0
2
misschatter
Frequently, our lightweight forwarders cannot connect to the Splunk server to send log tail output and we end up miss...
by misschatter Engager in Getting Data In 09-22-2010
3 1
3
1
Ron_Naken
If a LWF has a large number of files to monitor, what settings can be used to help ensure that consuming/monitoring t...
by Ron_Naken Splunk Employee Splunk Employee in Getting Data In 09-22-2010
3 2
3
2
Stan
Since I usually turned of splunkd service on my local machine and only turn it back on when I need to do some log sea...
by Stan New Member in Getting Data In 09-21-2010
0 1
0
1
dexpeterson
I just downloaded and installed splunk 4.1.4 and installed on WIN7 laptop. Upon reboot of my system, the CPU pegged ...
by dexpeterson Explorer in Getting Data In 09-21-2010
1 8
1
8
muebel
I have a fschange stanza configured as such [fschange:/path/to/file] disabled = false pollPeriod = 300 fullEvent = t...
by SplunkTrust SplunkTrust in Getting Data In 09-21-2010
1 3
1
3
Branden
I've been using the default "main" index for all my indexing. I'm at the point where I think it would be best to bran...
by Branden Builder in Getting Data In 09-21-2010
1 5
1
5
berniefieldhous
Hi... I'm trying to import 'thousands' of old event logs into Splunk to setup a searchable database.... I can enter...
by berniefieldhous Engager in Getting Data In 09-21-2010
2 3
2
3
Steve_Litras
I'm trying to take data from specific systems and, after indexing it, forward it to a third party for other analysis....
by Steve_Litras Path Finder in Getting Data In 09-20-2010
3 3
3
3
Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...
Top Solution Authors