Getting Data In

Getting Data In
Community Activity
Joffer
I'm getting frustrated with one server ending up in my index with both "hostname" and "hostname.domainname" depending...
by Joffer Path Finder in Getting Data In 07-25-2010
1 2
1
2
noahjscales
Hi. I have a new 4.1.4 free license install running on a VM. On the same server running Splunk, I have a /var/log th...
by noahjscales Explorer in Getting Data In 07-24-2010
0 2
0
2
mmattek
We are upgrading from splunk 3 to 4. We previously had sourcetypes with "-" in them. It looks like these aren't suppo...
by mmattek Path Finder in Getting Data In 07-22-2010
1 3
1
3
morningwood
We are currently performing a POC using Splunk 4.1.3 to index Blue Coat proxy data. Our test Splunk license is for 20...
by morningwood Explorer in Getting Data In 07-22-2010
1 5
1
5
remy06
Hi, How do I get splunk to show the date and time correctly based on the event?For example if I have the following e...
by remy06 Contributor in Getting Data In 07-22-2010
2 1
2
1
Jason
I have data coming in in the format "data1","data2","data3" from F5. however, some events contain " and some contain...
by Jason Motivator in Getting Data In 07-21-2010
6 7
6
7
rictersmith
We are evaluating Splunk 4, and one of the interests from our managment team is to know if Splunk can assist us with ...
by rictersmith Engager in Getting Data In 07-21-2010
3 7
3
7
Jason
I've tried everything and it seems I still can't get my stanzas in props.conf and transforms.conf to overwride source...
by Jason Motivator in Getting Data In 07-21-2010
1 3
1
3
pheezy
There used to be a Splunk2Nagios application that came with Splunk, and it worked very well. When 4.x was released i...
by pheezy Explorer in Getting Data In 07-21-2010
5 4
5
4
mctester
I need to add a new data input from a mount, but I have a distributed architecture (one forwarder / search head and t...
by mctester Communicator in Getting Data In 07-20-2010
0 1
0
1
kaplan71
Hi there -- I completed installing the latest version of Splunk on two systems where the first is the server, and th...
by kaplan71 New Member in Getting Data In 07-20-2010
0 2
0
2
marcoscala
Hi All! I'm trying to push Splunk to a Customer to index huge amount of data (almost 4.5GB/10M events per day). Th...
by marcoscala Builder in Getting Data In 07-19-2010
2 4
2
4
Starlette
I am forwarding a single source (file) from kiwisyslog with LFW to the indexer, so got 1 sourcetype [kiwisyslog] The...
by Starlette Contributor in Getting Data In 07-19-2010
2 5
2
5
heterodyned
I tried searching for documentation on how to implement filters for directories ( in fschange) Could someone let me...
by heterodyned Path Finder in Getting Data In 07-19-2010
1 3
1
3
empath
I've got a log file which tracks some call statistics. For some reason, about half of these, Splunk has them as bein...
by empath Explorer in Getting Data In 07-17-2010
1 4
1
4
skippylou
I see alot in the docs, etc. that show how to set limits on buckets, etc. I can't seem to find out if there is a way...
by skippylou Communicator in Getting Data In 07-17-2010
1 5
1
5
antinym
I backed up all my data, moved it to a larger secondary drive. Uninstalled and re-installed splunk on top of the back...
by antinym New Member in Getting Data In 07-15-2010
0 3
0
3
Simeon
I am running a scripted input that outputs the "apachectl -S" configuration. I have set the proper permissions, test...
by Simeon Splunk Employee Splunk Employee in Getting Data In 07-15-2010
1 1
1
1
sony_1688
Hello, my problem is that I want to use splunk to copy the log from snmptrapd.log file to another file and clear the ...
by sony_1688 New Member in Getting Data In 07-15-2010
0 1
0
1
remy06
Hi, I have a windows 2003 server with apache installed. I will like to monitor its access logs on my splunk server r...
by remy06 Contributor in Getting Data In 07-15-2010
0 1
0
1
bbear
Hi All, I have been trying to get Splunk to strip off the timestamp and host of forwarded events but do not understa...
by bbear Explorer in Getting Data In 07-14-2010
1 3
1
3
mfrost8
I have a tree of files on a forwarder that looks something like the following: /foo/able/ /foo/baker/ /foo/charlie/ ...
by mfrost8 Builder in Getting Data In 07-14-2010
1 2
1
2
bbear
Greetings experts, I am using syslog-ng and Splunk on the same box. I have configure syslog-ng to pipe the incoming ...
by bbear Explorer in Getting Data In 07-14-2010
1 3
1
3
balbano
Apparently my indexer is stripping out the syslog-ng flag fields ([INFO], [WARNING], and [CRIT]) when indexing syslog...
by balbano Contributor in Getting Data In 07-14-2010
0 9
0
9
mfrost8
I'm trying to setup a Splunk search head. I'm really trying to convert an existing light-weight forwarder server to ...
by mfrost8 Builder in Getting Data In 07-14-2010
1 4
1
4
Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...