| Hi, I have used props.conf and transforms.conf to configure two different sourcetypes coming to Splunk from udp:514. ... by alextsui Path Finder in Getting Data In 07-28-2010 0 3 | 0 | 3 | ||
| I see the BIG-IP can send syslog for administrative activity. I want to send syslog for all the HTTP requests the loa... by Dan Splunk Employee 4 3 | 4 | 3 | ||
| I am running a pretty basic search such as this email="someemail@domain.com" OR email="someemail@domain.com" ... by Chris_R_ Splunk Employee 1 2 | 1 | 2 | ||
| I think I found the answer to my question when I was writing it. From http://www.splunk.com/base/Documentation/4.1/A... by Joffer Path Finder in Getting Data In 07-27-2010 0 2 | 0 | 2 | ||
| Hi folks, as DHCP logfiles contain huge headers, with always the same information, i will remove them, befor indexin... by simuvid Splunk Employee 2 2 | 2 | 2 | ||
| Hi, Just to check, I've a splunk forwarder that shows lesser events indexed than on the splunk indexer.Is it suppose... by remy06 Contributor in Getting Data In 07-27-2010 0 1 | 0 | 1 | ||
| When monitoring an EMC Clarion, the CLI tool to dump the logs simply dumps all logs from the device, including any pr... by Ron_Naken Splunk Employee 3 1 | 3 | 1 | ||
| I'm trying to enable SSO by proxying from Apache w/ mod_auth_kerb. The problems seems to be the contents of Remote-Us... by dmesler Explorer in Getting Data In 07-26-2010 2 2 | 2 | 2 | ||
| I'm getting frustrated with one server ending up in my index with both "hostname" and "hostname.domainname" depending... by Joffer Path Finder in Getting Data In 07-25-2010 1 2 | 1 | 2 | ||
| Hi. I have a new 4.1.4 free license install running on a VM. On the same server running Splunk, I have a /var/log th... by noahjscales Explorer in Getting Data In 07-24-2010 0 2 | 0 | 2 | ||
| We are upgrading from splunk 3 to 4. We previously had sourcetypes with "-" in them. It looks like these aren't suppo... by mmattek Path Finder in Getting Data In 07-22-2010 1 3 | 1 | 3 | ||
| We are currently performing a POC using Splunk 4.1.3 to index Blue Coat proxy data. Our test Splunk license is for 20... by morningwood Explorer in Getting Data In 07-22-2010 1 5 | 1 | 5 | ||
| Hi, How do I get splunk to show the date and time correctly based on the event?For example if I have the following e... by remy06 Contributor in Getting Data In 07-22-2010 2 1 | 2 | 1 | ||
| I have data coming in in the format "data1","data2","data3" from F5. however, some events contain " and some contain... by Jason Motivator in Getting Data In 07-21-2010 6 7 | 6 | 7 | ||
| We are evaluating Splunk 4, and one of the interests from our managment team is to know if Splunk can assist us with ... by rictersmith Engager in Getting Data In 07-21-2010 3 7 | 3 | 7 | ||
| I've tried everything and it seems I still can't get my stanzas in props.conf and transforms.conf to overwride source... by Jason Motivator in Getting Data In 07-21-2010 1 3 | 1 | 3 | ||
| There used to be a Splunk2Nagios application that came with Splunk, and it worked very well. When 4.x was released i... by pheezy Explorer in Getting Data In 07-21-2010 5 4 | 5 | 4 | ||
| I need to add a new data input from a mount, but I have a distributed architecture (one forwarder / search head and t... by mctester Communicator in Getting Data In 07-20-2010 0 1 | 0 | 1 | ||
| Hi there -- I completed installing the latest version of Splunk on two systems where the first is the server, and th... by kaplan71 New Member in Getting Data In 07-20-2010 0 2 | 0 | 2 | ||
| Hi All! I'm trying to push Splunk to a Customer to index huge amount of data (almost 4.5GB/10M events per day). Th... by marcoscala Builder in Getting Data In 07-19-2010 2 4 | 2 | 4 | ||
| I am forwarding a single source (file) from kiwisyslog with LFW to the indexer, so got 1 sourcetype [kiwisyslog] The... by Starlette Contributor in Getting Data In 07-19-2010 2 5 | 2 | 5 | ||
| I tried searching for documentation on how to implement filters for directories ( in fschange) Could someone let me... by heterodyned Path Finder in Getting Data In 07-19-2010 1 3 | 1 | 3 | ||
| I've got a log file which tracks some call statistics. For some reason, about half of these, Splunk has them as bein... by empath Explorer in Getting Data In 07-17-2010 1 4 | 1 | 4 | ||
| I see alot in the docs, etc. that show how to set limits on buckets, etc. I can't seem to find out if there is a way... by skippylou Communicator in Getting Data In 07-17-2010 1 5 | 1 | 5 | ||
| I backed up all my data, moved it to a larger secondary drive. Uninstalled and re-installed splunk on top of the back... by antinym New Member in Getting Data In 07-15-2010 0 3 | 0 | 3 |