Getting Data In

Getting Data In
Community Activity
rotten
I've noticed that the maxDist value in the props.conf on various lightweight forwarders varies. I've never explicit...
by rotten Communicator in Getting Data In 08-17-2010
1 1
1
1
timbCFCA
Can the Cisco Firewall addon be restricted to only analyze data from a specific source or sourcetype? I have reports...
by timbCFCA Path Finder in Getting Data In 08-17-2010
0 2
0
2
ruiaires
We've been having severe Splunk performance issues on the following system: Windows 2008 R2 Enterprise 64 with a 2 C...
by ruiaires Path Finder in Getting Data In 08-17-2010
0 3
0
3
muebel
I would like to install IIS on a Splunk Indexer. Is there any way that this would cause any issues?
by SplunkTrust SplunkTrust in Getting Data In 08-17-2010
1 1
1
1
jbidinger
I'm trying to monitor the xml files that define a Solaris service. These files live under /var/svc/manifest/.../*.xml...
by jbidinger Explorer in Getting Data In 08-16-2010
1 5
1
5
mpatnode
I tried "splunk train sourcetype filename sourcename" and received the same error. Then I found this answer and got...
by mpatnode Path Finder in Getting Data In 08-16-2010
1 2
1
2
kris2000
Hello All I have Splunk 4.1.4 (splunk-4.1.4-82143-Linux-i686.tgz) installed (on Linux i686 box). I'm currently f...
by kris2000 Explorer in Getting Data In 08-16-2010
2 6
2
6
maverick
Does Splunk have the ability to use different sets of credentials for different monitoring on Windows? It appears o...
by maverick Splunk Employee Splunk Employee in Getting Data In 08-16-2010
0 1
0
1
mfrost8
We recently started turning on 'autoLB' for our lightweight forwarders. We use the default value of 30 seconds for t...
by mfrost8 Builder in Getting Data In 08-15-2010
0 4
0
4
skippylou
So looking at the Indexes page in Manager, I can tell that one of my indexes has hit the size limit and is successful...
by skippylou Communicator in Getting Data In 08-14-2010
4 1
4
1
simuvid
Hi all, I have posted a similar question before, but I think I was not specific enough. What I mean is, when gettin...
by simuvid Splunk Employee Splunk Employee in Getting Data In 08-14-2010
0 2
0
2
christopherutz
We are standardizing some sourcetype names and had the idea to provide a "compatibility" app in which users could run...
by christopherutz Path Finder in Getting Data In 08-13-2010
1 3
1
3
leonardw
Does anyone know how to determine the volume of SYSLOG traffic coming into Splunk over a 30, 60, and 90 day period?
by leonardw Explorer in Getting Data In 08-13-2010
1 6
1
6
jeffa
I have two sourcetypes where the thousandth of a second portion of the timestamp is not padded w/ leading zeros if th...
by jeffa Path Finder in Getting Data In 08-13-2010
2 13
2
13
snowmizer
I would like to setup file system change monitoring on my Windows server (using fschange) where my users private fold...
by snowmizer Communicator in Getting Data In 08-13-2010
0 2
0
2
dhaffner
We have a huge sudden input of a specific sourcetype and it is overloading the license. Can we somehow block it or s...
by dhaffner Path Finder in Getting Data In 08-13-2010
1 5
1
5
jbanda
I installed the splunk for F5 app, and I'm trying to figure out how to get data from our 2 LTMs running ASM into splu...
by jbanda Path Finder in Getting Data In 08-13-2010
1 2
1
2
rv6abob
I understand there is an interface on a forwarder to find out the status of files that are being forwarded. Can that ...
by rv6abob Engager in Getting Data In 08-11-2010
0 1
0
1
mgherman
According to the documentation for Splunk version 3.x there is the ability to alias a sourcetype, however it does not...
by mgherman Explorer in Getting Data In 08-10-2010
0 1
0
1
wilsona
Hi, I cannot seem to get the cisco firewall add-on working with splunk for windows. Error is "TypeError: 'NoneType...
by wilsona New Member in Getting Data In 08-10-2010
0 3
0
3
woodchuck
hello everyone, I know there are many similar posts to this, and i have read a lot but i cant seem to get it to work...
by woodchuck New Member in Getting Data In 08-09-2010
0 2
0
2
ericjan
I have the following log structure. Splunk is configured to monitor /var/logs directory, and the host is defined by p...
by ericjan New Member in Getting Data In 08-09-2010
0 2
0
2
Saltie06
Is there a way to deserialize the LoggingEvent produced by Log4J when using the socket appender? Splunk appears to re...
by Saltie06 New Member in Getting Data In 08-09-2010
0 3
0
3
heterodyned
Hello Folks, I have two copies of inputs.conf, one is under the etc/apps/local directory ( created the local and pla...
by heterodyned Path Finder in Getting Data In 08-09-2010
0 2
0
2
cparham
This is related to http://answers.splunk.com/questions/2141/xml-log-source-type How would I remove line breaks found...
by cparham Explorer in Getting Data In 08-06-2010
1 4
1
4
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...
Top Solution Authors