Getting Data In

Getting Data In
Community Activity
drawks
Is there a way to see what files are being read by the various monitor/fschange stanzas in input.conf?
by drawks Explorer in Getting Data In 08-30-2010
2 2
2
2
twinspop
Receiving splunk server inputs.conf: [splunktcp://7900] Sending splunk server outputs.conf: [tcpout] defaultGroup...
by twinspop Influencer in Getting Data In 08-30-2010
0 11
0
11
southeringtonp
Is there a way to extract the hostname from an event, but force it to lower-case in the process? Extracting the host...
by southeringtonp Motivator in Getting Data In 08-28-2010
6 2
6
2
dwaddle
The operating system won't allow a non-root user to bind to ports < 1024. How can I get my splunkd, running as user ...
by SplunkTrust SplunkTrust in Getting Data In 08-27-2010
11 2
11
2
ericrobinson
Hello, I have a chart that show event counts split by source name. For our analysis, it is very important that we see...
by ericrobinson Path Finder in Getting Data In 08-27-2010
2 2
2
2
gsawyer1
for each [WinEventLog: ] stanza in inputs.conf, can you specify more than one entry for evt_dc_name? Because what i...
by gsawyer1 Engager in Getting Data In 08-26-2010
0 1
0
1
caphrim007
I was wondering if it were possible to do a mask on events in addition to sending them to a separate index. Since th...
by caphrim007 Path Finder in Getting Data In 08-25-2010
0 2
0
2
aaronzabell
I have a bunch of light forwarders sending data to a central heavy forwarder which sends the data to the main indexer...
by aaronzabell Path Finder in Getting Data In 08-25-2010
0 7
0
7
dnolan
Is there a way with the basic Forwarder to configure it to send events to server A if its up, and to server B only if...
by dnolan Explorer in Getting Data In 08-25-2010
1 4
1
4
chris
Hi To update our splunk forwarders we use puppet. Puppet first removes the splunk package and then installs the new...
by chris Motivator in Getting Data In 08-25-2010
0 3
0
3
sunnykkim
Hi, I have a forwarder sending a syslog file to the receiver. The syslog has entries like: Jul 27 09:50:21 ip-10-...
by sunnykkim Engager in Getting Data In 08-25-2010
1 3
1
3
Chris_R_
A websphere server, in particular the websphere_trlog appear to be getting over indexed by a huge amount Checking ht...
by Chris_R_ Splunk Employee Splunk Employee in Getting Data In 08-24-2010
0 4
0
4
Jason
Has anyone put into production an input stanza that runs an fschange on all of C:\windows? A) what is the performanc...
by Jason Motivator in Getting Data In 08-24-2010
1 5
1
5
adickerson
I am trying to figure how to use the rest api. I can't find much documentation on it for 4.0.3.
by adickerson New Member in Getting Data In 08-24-2010
0 1
0
1
adamw
I have my splunk instance set up to receive data on a TCP port, sourcetype it, then output it with to a Splunk receiv...
by adamw Communicator in Getting Data In 08-24-2010
3 5
3
5
Nicholas_Key
Hi all, Quick question about summary indexing: I have this configuration in the savedsearches.conf [esxtop_Group_C...
by Nicholas_Key Splunk Employee Splunk Employee in Getting Data In 08-22-2010
0 1
0
1
aaronzabell
I have a bunch of light forwarders sending data to a central heavy forwarder which then sends the data to the main in...
by aaronzabell Path Finder in Getting Data In 08-20-2010
0 6
0
6
remy06
Hi, I like to monitor certain folders(for eg. C:\myfolder) and its subfolders/files on a windows server. I've enable...
by remy06 Contributor in Getting Data In 08-20-2010
0 3
0
3
remy06
hi, I'm trying to configure splunk to display the time based on the event. The event's timestamp format is somethin...
by remy06 Contributor in Getting Data In 08-20-2010
0 2
0
2
danrand
The process splunk-regmon.exe is running 95%-99% CPU (Splunk 3.1.4, WinXP SP3 as a VM in VMware Fusion 3.1.1). How do...
by danrand Explorer in Getting Data In 08-19-2010
0 2
0
2
pdevlin
What events should I be watching for in my Splunk logs? Does anyone have a list of specific error codes that would i...
by pdevlin Explorer in Getting Data In 08-19-2010
1 2
1
2
carmackd
I'm having problems with indexing a particular log source, which is slowing down. It started off strong but continue...
by carmackd Communicator in Getting Data In 08-19-2010
1 6
1
6
silvermail
Hello all, Not sure if anyone has encountered this before, but I have events that are purged off but when I am in th...
by silvermail Path Finder in Getting Data In 08-19-2010
0 3
0
3
silvermail
Hello guys, Been trying to get this to work but to no avail... I have a CSV file that goes like this: pid hostname...
by silvermail Path Finder in Getting Data In 08-19-2010
0 3
0
3
aaronzabell
Splunk is currently indexing the logs for all of my companies switches and routers. It's a mishmash of Dell and Cisco...
by aaronzabell Path Finder in Getting Data In 08-18-2010
0 2
0
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...