| Other than the oneshot... how would one toss a file into an index through the CLI? I likely missed it in the documen... by hiddenkirby Contributor in Getting Data In 10-06-2010 3 2 | 3 | 2 | ||
| We're setting up a custom data input and I'm wondering whether it's a bad idea to just write everything to WinEventLo... by sideview SplunkTrust 0 2 | 0 | 2 | ||
| I have a script that runs in an app on my forwarders every 12 hours. Or at least that's what it was doing until it ab... by Branden Builder in Getting Data In 10-05-2010 0 5 | 0 | 5 | ||
| Hi, I recently had to go back and add some historical data that was generated prior to splunk being installed on som... by mgherman Explorer in Getting Data In 10-05-2010 1 2 | 1 | 2 | ||
| I am using the "Map users directly" config from here - http://www.splunk.com/base/Documentation/4.1.5/Admin/Setupus... by twgtech New Member in Getting Data In 10-05-2010 0 4 | 0 | 4 | ||
| I have a date and time timestamp that looks like DATABASE|20100226|123918|20100226|083918| and I want to extract the ... by bc_unixadm Explorer in Getting Data In 10-05-2010 1 3 | 1 | 3 | ||
| We have some logs being written by a buffered writer. This means that occasionally (depending on when the buffer is ... by christopherutz Path Finder in Getting Data In 10-05-2010 2 7 | 2 | 7 | ||
| Splunk's web GUI makes a few external calls out, e.g. to load the list of available apps from Splunkbase. If my cor... by Justin_Grant Contributor in Getting Data In 10-05-2010 0 2 | 0 | 2 | ||
| Customer has a log file that is failing to break correctly: Some of the events in the file are single line events. Ot... by Genti Splunk Employee 0 2 | 0 | 2 | ||
| I am trying to find a search for index volume over time for licensing tracking. I need to search by index or by hos... by mctester Communicator in Getting Data In 10-04-2010 2 3 | 2 | 3 | ||
| I have set the UDP syslog port to set hostnames based on DNS. For several hosts this is working fine, however one of ... by Kyle_Brandt Path Finder in Getting Data In 10-04-2010 0 1 | 0 | 1 | ||
| Hello, I have a syslogNG with a forwader to splunkindexer, the syslogNG contains 1000+ hosts Default this will be a ... by Starlette Contributor in Getting Data In 10-04-2010 2 2 | 2 | 2 | ||
| I have log files from a custom app we wrote that is entirely in hex. To splunk it, I understand I might be able to c... by highiqboy Explorer in Getting Data In 10-03-2010 2 1 | 2 | 1 | ||
| I have a special user (her name is "dashboard") that needs a session timeout of 0. Is it possible to set no timeout ... by the_wolverine Champion in Getting Data In 10-03-2010 3 2 | 3 | 2 | ||
| Hello all - I am in the process of evaluating Splunk (for windows), and found the Cisco ASA and Pix Firewall addon... by dclick New Member in Getting Data In 10-01-2010 0 8 | 0 | 8 | ||
| Splunk server : Windows XP SP3. Remote servers : Windos XP SP2 I am not permitted to install ANY software on the rem... by landau351 Engager in Getting Data In 10-01-2010 2 1 | 2 | 1 | ||
| I have about 8 files of the same kind of event logs which I require Splunk to index. Splunk managed to index 6 of the... by remy06 Contributor in Getting Data In 10-01-2010 3 1 | 3 | 1 | ||
| Before I ask my question, this is my environment. 1 forwarder 4 indexers 1 search head I am trying to setup sever... by ultra Explorer in Getting Data In 09-30-2010 0 3 | 0 | 3 | ||
| Hi, Is there a search that can return the list of indexes configured on a Splunk Indexer? Or is the only way to loo... by Derek Path Finder in Getting Data In 09-30-2010 0 2 | 0 | 2 | ||
| Can I use more than one DEST_KEY? For example DEST_KEY=_MetaData:Index,MetaData:Sourcetype FORMAT=sourcetype::VPN,i... by carmackd Communicator in Getting Data In 09-29-2010 0 1 | 0 | 1 | ||
| I'm using the forwarder license on my search head. I've disabled all inputs, and any extra apps. Yet I still get lice... by twinspop Influencer in Getting Data In 09-29-2010 0 2 | 0 | 2 | ||
| I have a script that outputs between 300 and 800 lines. The output seems to be truncated after 138 lines. Is there ... by rsigle Explorer in Getting Data In 09-28-2010 0 3 | 0 | 3 | ||
| Hi, I am unable to extract a valid _time from the following log: 0168 004 07:59:03 09:01:35 0062 asdfghj ee bonfany... by imrago Contributor in Getting Data In 09-27-2010 0 10 | 0 | 10 | ||
| I'm unable to force sourcetype from props.conf. Relatively new to splunk, am trying to setup logging of solaris /var... by pmr Explorer in Getting Data In 09-27-2010 0 2 | 0 | 2 | ||
| We have a log file which contains a 7 digit second timestamp like the below: 08:30:00.2124216 We periodically need t... by briang67 Communicator in Getting Data In 09-25-2010 1 2 | 1 | 2 |