Getting Data In

Getting Data In
Community Activity
dexpeterson
I just downloaded and installed splunk 4.1.4 and installed on WIN7 laptop. Upon reboot of my system, the CPU pegged ...
by dexpeterson Explorer in Getting Data In 09-21-2010
1 8
1
8
muebel
I have a fschange stanza configured as such [fschange:/path/to/file] disabled = false pollPeriod = 300 fullEvent = t...
by SplunkTrust SplunkTrust in Getting Data In 09-21-2010
1 3
1
3
Branden
I've been using the default "main" index for all my indexing. I'm at the point where I think it would be best to bran...
by Branden Builder in Getting Data In 09-21-2010
1 5
1
5
berniefieldhous
Hi... I'm trying to import 'thousands' of old event logs into Splunk to setup a searchable database.... I can enter...
by berniefieldhous Engager in Getting Data In 09-21-2010
2 3
2
3
Steve_Litras
I'm trying to take data from specific systems and, after indexing it, forward it to a third party for other analysis....
by Steve_Litras Path Finder in Getting Data In 09-20-2010
3 3
3
3
Josh
Hi, Now I know you can set the following in indexes.conf maxTotalDataSizeMB = 500000 which sets the max size of the ...
by Josh Path Finder in Getting Data In 09-20-2010
1 8
1
8
Branden
I am writing an app for my team to use. Let's call the app xyz. The app will make use of various inputs, saved search...
by Branden Builder in Getting Data In 09-20-2010
0 2
0
2
Peter_B
We're using the unix app to monitor our linux machines. One of the files we need to monitor is /var/log/secure. The u...
by Peter_B Explorer in Getting Data In 09-20-2010
2 2
2
2
liviab
Hi, I'm using Splunk to index logs which timestamp is in the format Y2010M09D17H10N07S00. As Splunk couldn't understa...
by liviab Explorer in Getting Data In 09-20-2010
2 5
2
5
parallaxed
We have a configuration that's been idling for over two days, and instead of processing locations that the tailing pr...
by parallaxed Path Finder in Getting Data In 09-20-2010
2 14
2
14
iokoluke
Hello, We are looking at deploying splunk for our application servers log files, these log files are about 3GB per d...
by iokoluke New Member in Getting Data In 09-17-2010
0 2
0
2
muebel
I have splunk set up on a few redhat boxes, and I am getting duplicate events from them. One event will list the hos...
by SplunkTrust SplunkTrust in Getting Data In 09-17-2010
0 2
0
2
pde
I have records that consist of fairly large (200+ lines, > 20 Kb per record) XML documents. When I export the result...
by pde Path Finder in Getting Data In 09-17-2010
0 2
0
2
ultra
Hi, I'm new to splunk, so my question might be lame. I am trying to setup a splunk lightweight forwarder, my problem ...
by ultra Explorer in Getting Data In 09-17-2010
0 1
0
1
Caio_Santos
One Splunk instance is forwarding data to a receiver, however the receiver is indexing the data and getting the wrong...
by Caio_Santos Path Finder in Getting Data In 09-16-2010
0 2
0
2
tedder
So I have the following in inputs.conf: [udp://10005] connection_host = index = serverlogs sourcetype = syslog disab...
by tedder Communicator in Getting Data In 09-16-2010
0 3
0
3
Caio_Santos
I'm forwarding data from a windows splunk instance to a freebsd. I checked the index that i'm forwarding data to, so ...
by Caio_Santos Path Finder in Getting Data In 09-15-2010
0 1
0
1
dleung
I am checking out a sample application where an eventtype's search contains "sourcetype=..." . I having difficulty d...
by dleung Splunk Employee Splunk Employee in Getting Data In 09-14-2010
1 4
1
4
Caio_Santos
How do I know which index forwarded data goes to receiver instance ? I'm not sure about that, but i've created 2 inde...
by Caio_Santos Path Finder in Getting Data In 09-14-2010
1 2
1
2
devilears
How do I monitor how often my users are using Splunk?
by devilears New Member in Getting Data In 09-14-2010
0 1
0
1
Ant1D
Good Morning, I have a question that I would love to be answered if possible.  I have written the following xml c...
by Ant1D Motivator in Getting Data In 09-14-2010
0 11
0
11
melonman
Hi there, I would like to know how to handle international character code in Splunk. The environment I have here i...
by melonman Motivator in Getting Data In 09-14-2010
0 6
0
6
chjpcert
I've been testing Splunk for several months now, and am consistently having problems with duplicate events appearing ...
by chjpcert Explorer in Getting Data In 09-14-2010
1 8
1
8
rgcox1
So we know about lost forwarders, but how about lost logs? I recently discovered that some of my Windows systems were...
by rgcox1 Communicator in Getting Data In 09-13-2010
0 4
0
4
Nicholas_Key
Hi all, I have the following output from a Perl script that runs every 5 mins: 09-13-2010 16:21:20 - Inventory Rep...
by Nicholas_Key Splunk Employee Splunk Employee in Getting Data In 09-13-2010
1 2
1
2
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Solution Authors