Getting Data In

Getting Data In
Community Activity
alextsui
Hi, I have used props.conf and transforms.conf to configure two different sourcetypes coming to Splunk from udp:514. ...
by alextsui Path Finder in Getting Data In 07-28-2010
0 3
0
3
Dan
I see the BIG-IP can send syslog for administrative activity. I want to send syslog for all the HTTP requests the loa...
by Dan Splunk Employee Splunk Employee in Getting Data In 07-27-2010
4 3
4
3
Chris_R_
I am running a pretty basic search such as this email="someemail@domain.com" OR email="someemail@domain.com" ...
by Chris_R_ Splunk Employee Splunk Employee in Getting Data In 07-27-2010
1 2
1
2
Joffer
I think I found the answer to my question when I was writing it. From http://www.splunk.com/base/Documentation/4.1/A...
by Joffer Path Finder in Getting Data In 07-27-2010
0 2
0
2
simuvid
Hi folks, as DHCP logfiles contain huge headers, with always the same information, i will remove them, befor indexin...
by simuvid Splunk Employee Splunk Employee in Getting Data In 07-27-2010
2 2
2
2
remy06
Hi, Just to check, I've a splunk forwarder that shows lesser events indexed than on the splunk indexer.Is it suppose...
by remy06 Contributor in Getting Data In 07-27-2010
0 1
0
1
Ron_Naken
When monitoring an EMC Clarion, the CLI tool to dump the logs simply dumps all logs from the device, including any pr...
by Ron_Naken Splunk Employee Splunk Employee in Getting Data In 07-26-2010
3 1
3
1
dmesler
I'm trying to enable SSO by proxying from Apache w/ mod_auth_kerb. The problems seems to be the contents of Remote-Us...
by dmesler Explorer in Getting Data In 07-26-2010
2 2
2
2
Joffer
I'm getting frustrated with one server ending up in my index with both "hostname" and "hostname.domainname" depending...
by Joffer Path Finder in Getting Data In 07-25-2010
1 2
1
2
noahjscales
Hi. I have a new 4.1.4 free license install running on a VM. On the same server running Splunk, I have a /var/log th...
by noahjscales Explorer in Getting Data In 07-24-2010
0 2
0
2
mmattek
We are upgrading from splunk 3 to 4. We previously had sourcetypes with "-" in them. It looks like these aren't suppo...
by mmattek Path Finder in Getting Data In 07-22-2010
1 3
1
3
morningwood
We are currently performing a POC using Splunk 4.1.3 to index Blue Coat proxy data. Our test Splunk license is for 20...
by morningwood Explorer in Getting Data In 07-22-2010
1 5
1
5
remy06
Hi, How do I get splunk to show the date and time correctly based on the event?For example if I have the following e...
by remy06 Contributor in Getting Data In 07-22-2010
2 1
2
1
Jason
I have data coming in in the format "data1","data2","data3" from F5. however, some events contain " and some contain...
by Jason Motivator in Getting Data In 07-21-2010
6 7
6
7
rictersmith
We are evaluating Splunk 4, and one of the interests from our managment team is to know if Splunk can assist us with ...
by rictersmith Engager in Getting Data In 07-21-2010
3 7
3
7
Jason
I've tried everything and it seems I still can't get my stanzas in props.conf and transforms.conf to overwride source...
by Jason Motivator in Getting Data In 07-21-2010
1 3
1
3
pheezy
There used to be a Splunk2Nagios application that came with Splunk, and it worked very well. When 4.x was released i...
by pheezy Explorer in Getting Data In 07-21-2010
5 4
5
4
mctester
I need to add a new data input from a mount, but I have a distributed architecture (one forwarder / search head and t...
by mctester Communicator in Getting Data In 07-20-2010
0 1
0
1
kaplan71
Hi there -- I completed installing the latest version of Splunk on two systems where the first is the server, and th...
by kaplan71 New Member in Getting Data In 07-20-2010
0 2
0
2
marcoscala
Hi All! I'm trying to push Splunk to a Customer to index huge amount of data (almost 4.5GB/10M events per day). Th...
by marcoscala Builder in Getting Data In 07-19-2010
2 4
2
4
Starlette
I am forwarding a single source (file) from kiwisyslog with LFW to the indexer, so got 1 sourcetype [kiwisyslog] The...
by Starlette Contributor in Getting Data In 07-19-2010
2 5
2
5
heterodyned
I tried searching for documentation on how to implement filters for directories ( in fschange) Could someone let me...
by heterodyned Path Finder in Getting Data In 07-19-2010
1 3
1
3
empath
I've got a log file which tracks some call statistics. For some reason, about half of these, Splunk has them as bein...
by empath Explorer in Getting Data In 07-17-2010
1 4
1
4
skippylou
I see alot in the docs, etc. that show how to set limits on buckets, etc. I can't seem to find out if there is a way...
by skippylou Communicator in Getting Data In 07-17-2010
1 5
1
5
antinym
I backed up all my data, moved it to a larger secondary drive. Uninstalled and re-installed splunk on top of the back...
by antinym New Member in Getting Data In 07-15-2010
0 3
0
3
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors