Getting Data In

Getting Data In
Community Activity
Jason
Has anyone put into production an input stanza that runs an fschange on all of C:\windows? A) what is the performanc...
by Jason Motivator in Getting Data In 08-24-2010
1 5
1
5
adickerson
I am trying to figure how to use the rest api. I can't find much documentation on it for 4.0.3.
by adickerson New Member in Getting Data In 08-24-2010
0 1
0
1
adamw
I have my splunk instance set up to receive data on a TCP port, sourcetype it, then output it with to a Splunk receiv...
by adamw Communicator in Getting Data In 08-24-2010
3 5
3
5
Nicholas_Key
Hi all, Quick question about summary indexing: I have this configuration in the savedsearches.conf [esxtop_Group_C...
by Nicholas_Key Splunk Employee Splunk Employee in Getting Data In 08-22-2010
0 1
0
1
aaronzabell
I have a bunch of light forwarders sending data to a central heavy forwarder which then sends the data to the main in...
by aaronzabell Path Finder in Getting Data In 08-20-2010
0 6
0
6
remy06
Hi, I like to monitor certain folders(for eg. C:\myfolder) and its subfolders/files on a windows server. I've enable...
by remy06 Contributor in Getting Data In 08-20-2010
0 3
0
3
remy06
hi, I'm trying to configure splunk to display the time based on the event. The event's timestamp format is somethin...
by remy06 Contributor in Getting Data In 08-20-2010
0 2
0
2
danrand
The process splunk-regmon.exe is running 95%-99% CPU (Splunk 3.1.4, WinXP SP3 as a VM in VMware Fusion 3.1.1). How do...
by danrand Explorer in Getting Data In 08-19-2010
0 2
0
2
pdevlin
What events should I be watching for in my Splunk logs? Does anyone have a list of specific error codes that would i...
by pdevlin Explorer in Getting Data In 08-19-2010
1 2
1
2
carmackd
I'm having problems with indexing a particular log source, which is slowing down. It started off strong but continue...
by carmackd Communicator in Getting Data In 08-19-2010
1 6
1
6
silvermail
Hello all, Not sure if anyone has encountered this before, but I have events that are purged off but when I am in th...
by silvermail Path Finder in Getting Data In 08-19-2010
0 3
0
3
silvermail
Hello guys, Been trying to get this to work but to no avail... I have a CSV file that goes like this: pid hostname...
by silvermail Path Finder in Getting Data In 08-19-2010
0 3
0
3
aaronzabell
Splunk is currently indexing the logs for all of my companies switches and routers. It's a mishmash of Dell and Cisco...
by aaronzabell Path Finder in Getting Data In 08-18-2010
0 2
0
2
Nicholas_Key
Hi all, is there a way to translate this event into a table? This is what I get with my search string: index="vmware...
by Nicholas_Key Splunk Employee Splunk Employee in Getting Data In 08-18-2010
0 5
0
5
Branden
Hi. Seems like a lot of people have a question similar to this, but maybe I am missing something simple. I'm monit...
by Branden Builder in Getting Data In 08-18-2010
1 6
1
6
parallaxed
Looks like MetaData:Source should be used, but despite many variations and | extract reload=t, I can't seem to get th...
by parallaxed Path Finder in Getting Data In 08-18-2010
0 4
0
4
edgustaf
We run a central Syslog-NG server, which all the logs for the servers and devices we care about get sent to. We use ...
by edgustaf Explorer in Getting Data In 08-17-2010
3 4
3
4
erga00
I have a folder containing logs as below. I want to exclude all directories not named DONTINDEX_* and index the conte...
by erga00 Path Finder in Getting Data In 08-17-2010
3 6
3
6
rotten
I've noticed that the maxDist value in the props.conf on various lightweight forwarders varies. I've never explicit...
by rotten Communicator in Getting Data In 08-17-2010
1 1
1
1
timbCFCA
Can the Cisco Firewall addon be restricted to only analyze data from a specific source or sourcetype? I have reports...
by timbCFCA Path Finder in Getting Data In 08-17-2010
0 2
0
2
ruiaires
We've been having severe Splunk performance issues on the following system: Windows 2008 R2 Enterprise 64 with a 2 C...
by ruiaires Path Finder in Getting Data In 08-17-2010
0 3
0
3
muebel
I would like to install IIS on a Splunk Indexer. Is there any way that this would cause any issues?
by SplunkTrust SplunkTrust in Getting Data In 08-17-2010
1 1
1
1
jbidinger
I'm trying to monitor the xml files that define a Solaris service. These files live under /var/svc/manifest/.../*.xml...
by jbidinger Explorer in Getting Data In 08-16-2010
1 5
1
5
mpatnode
I tried "splunk train sourcetype filename sourcename" and received the same error. Then I found this answer and got...
by mpatnode Path Finder in Getting Data In 08-16-2010
1 2
1
2
kris2000
Hello All I have Splunk 4.1.4 (splunk-4.1.4-82143-Linux-i686.tgz) installed (on Linux i686 box). I'm currently f...
by kris2000 Explorer in Getting Data In 08-16-2010
2 6
2
6
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...
Top Solution Authors