Getting Data In

Getting Data In
Community Activity
gsawyer1
I'm in a Windows environment, trying to set up forwarding to my indexer, all on Windows 2008 servers. So, I made sur...
by gsawyer1 Engager in Getting Data In 09-02-2010
0 5
0
5
maverick
I’m currently running Splunk on my Windows XP SP3 and I'm trying to get a couple scripts to run after an alert trigge...
by maverick Splunk Employee Splunk Employee in Getting Data In 09-02-2010
3 4
3
4
dalgibbard
Hi all, Basically for example's sake; lets say i have 45 web server clients logging to a Splunk Indexer and it is the...
by dalgibbard Engager in Getting Data In 09-02-2010
0 5
0
5
local_graph_2
I am running Splunk on Windows 7 64 bit and configured data adapters for syslog on TCP and UDP. I can see via Wiresha...
by local_graph_2 New Member in Getting Data In 09-01-2010
0 6
0
6
wrightp
I want to get logs and data from my sidewinder firewall running 7.0.0.06. How do I do it?
by wrightp New Member in Getting Data In 09-01-2010
0 2
0
2
jerry_john
I installed Splunk on my Windows XP machine and I'm trying to setup the "Source" to "Monitor a file or directory" whi...
by jerry_john Engager in Getting Data In 09-01-2010
1 2
1
2
Ellen
All of a sudden my 4.0.9 Splunk server is no longer forwarding the WinEventLog:Security logs onto my 4.1.4 Linux inde...
by Ellen Splunk Employee Splunk Employee in Getting Data In 09-01-2010
2 1
2
1
skattamu
I am trying batch upload like this from a light forwarder. But the files are not being consumed (there are only 2 sma...
by skattamu New Member in Getting Data In 09-01-2010
0 5
0
5
hulahoop
I have a long list of hosts/sources/sourcetypes I want to restrict a user to. Can I define a macro, then reference t...
by hulahoop Splunk Employee Splunk Employee in Getting Data In 09-01-2010
1 6
1
6
DyJohnnY
Hi, Is there a way to have this search do following: get me all sources that related to windows (win*) - then calcul...
by DyJohnnY Explorer in Getting Data In 09-01-2010
0 2
0
2
Branden
I know that Splunk can parse all different types of timestamps, but I've got a funky one. Here's the situation: AIX ...
by Branden Builder in Getting Data In 08-31-2010
1 6
1
6
Ant1D
Hi, My instance of Splunk is monitoring a server log file that is updated at periods throughout the day. Splunk has ...
by Ant1D Motivator in Getting Data In 08-31-2010
0 5
0
5
Daniel
I would like to know wether it is possible to filter remote windows eventlog based on the groups inside wmi.conf. I h...
by Daniel Explorer in Getting Data In 08-31-2010
0 6
0
6
Lowell
We have a monitoring system (WhatsUpGold) that periodically logs in to our windows machines and checks various condit...
by Lowell Super Champion in Getting Data In 08-30-2010
1 2
1
2
drawks
Is there a way to see what files are being read by the various monitor/fschange stanzas in input.conf?
by drawks Explorer in Getting Data In 08-30-2010
2 2
2
2
twinspop
Receiving splunk server inputs.conf: [splunktcp://7900] Sending splunk server outputs.conf: [tcpout] defaultGroup...
by twinspop Influencer in Getting Data In 08-30-2010
0 11
0
11
southeringtonp
Is there a way to extract the hostname from an event, but force it to lower-case in the process? Extracting the host...
by southeringtonp Motivator in Getting Data In 08-28-2010
6 2
6
2
dwaddle
The operating system won't allow a non-root user to bind to ports < 1024. How can I get my splunkd, running as user ...
by SplunkTrust SplunkTrust in Getting Data In 08-27-2010
11 2
11
2
ericrobinson
Hello, I have a chart that show event counts split by source name. For our analysis, it is very important that we see...
by ericrobinson Path Finder in Getting Data In 08-27-2010
2 2
2
2
gsawyer1
for each [WinEventLog: ] stanza in inputs.conf, can you specify more than one entry for evt_dc_name? Because what i...
by gsawyer1 Engager in Getting Data In 08-26-2010
0 1
0
1
caphrim007
I was wondering if it were possible to do a mask on events in addition to sending them to a separate index. Since th...
by caphrim007 Path Finder in Getting Data In 08-25-2010
0 2
0
2
aaronzabell
I have a bunch of light forwarders sending data to a central heavy forwarder which sends the data to the main indexer...
by aaronzabell Path Finder in Getting Data In 08-25-2010
0 7
0
7
dnolan
Is there a way with the basic Forwarder to configure it to send events to server A if its up, and to server B only if...
by dnolan Explorer in Getting Data In 08-25-2010
1 4
1
4
chris
Hi To update our splunk forwarders we use puppet. Puppet first removes the splunk package and then installs the new...
by chris Motivator in Getting Data In 08-25-2010
0 3
0
3
sunnykkim
Hi, I have a forwarder sending a syslog file to the receiver. The syslog has entries like: Jul 27 09:50:21 ip-10-...
by sunnykkim Engager in Getting Data In 08-25-2010
1 3
1
3
Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...
Top Solution Authors