| How to send syslog-ng messages to Splunk properly? I'm using Free 'splunk-4.1.4-82143-linux-2.6-intel.deb' and 'syslo... by Katey Explorer in Getting Data In 08-03-2010 3 4 | 3 | 4 | ||
| Is it possible to use the oneshot command from a remote server. Essentially we have a series of logs that are not ab... by bnolen Path Finder in Getting Data In 08-03-2010 0 4 | 0 | 4 | ||
| I have a log, representing data from multiple hosts, with lines like this: 7/30/2010 4:11:52 PM host=OAK06VMH load=5... by Justin_Grant Contributor in Getting Data In 07-31-2010 1 1 | 1 | 1 | ||
| In other words, can I set 30 days OR 700G (for instance)? The docs aren't clear on how to do that. by bfaber Communicator in Getting Data In 07-31-2010 0 1 | 0 | 1 | ||
| Hello all, I'm new to Splunk, so please bear with me as I ask a really n00bish question. Is it necessary to define y... by afroblanco Engager in Getting Data In 07-30-2010 1 3 | 1 | 3 | ||
| On Windows, I want to set the homePath in my indexes.conf file for a new index I created, which is located on my E:\ ... by maverick Splunk Employee 0 1 | 0 | 1 | ||
| I have a WMI Perf counter query that always returns zero in Splunk as the values are always < 1 second. It looks like... by COH New Member in Getting Data In 07-30-2010 0 1 | 0 | 1 | ||
| I am trying to analyse a squid access log for top 10 reports (top sources, top destinations, etc.) I imported the lo... by njathan Explorer in Getting Data In 07-30-2010 1 5 | 1 | 5 | ||
| In this answer I can see there is ways to get the status of the tailing processor on a box. Only problem is it looks ... by zscgeek Path Finder in Getting Data In 07-30-2010 0 2 | 0 | 2 | ||
| I turned off the syslog server running alongside Splunk and configured Splunk to listen on 514. It indexed the forwar... by noahjscales Explorer in Getting Data In 07-30-2010 1 3 | 1 | 3 | ||
| Hi There.. What is the best way to accomplish the following: I have several users who are on XP notebooks who need to... by Sparky Engager in Getting Data In 07-29-2010 1 1 | 1 | 1 | ||
| I have version 4.1 and have it set up to recieve syslog data directly from various servers but I only want to hold th... by miguel255 Engager in Getting Data In 07-29-2010 1 1 | 1 | 1 | ||
| Hi there.Lets see if someone can help me with this. We have this requirement: We have several saved searches and rep... by hbazan Path Finder in Getting Data In 07-29-2010 2 5 | 2 | 5 | ||
| FORMAT = <string> * The special identifier $0 represents what was in the DEST_KEY before this regex was performed. ... by wollinet Path Finder in Getting Data In 07-29-2010 0 6 | 0 | 6 | ||
| This would be a very trivial question, but what are the circumstances when splunk re-indexes new data? Replacing an e... by heterodyned Path Finder in Getting Data In 07-29-2010 0 5 | 0 | 5 | ||
| Hello , We have splunk 3.4.6 installed on one of our servers locally, on that server it was configured so that it ge... by kranthi New Member in Getting Data In 07-28-2010 0 1 | 0 | 1 | ||
| According to the wiki the best practice for syslog is having another program write the files to disk then have Splunk... by Jason Motivator in Getting Data In 07-28-2010 1 1 | 1 | 1 | ||
| Hi, I have used props.conf and transforms.conf to configure two different sourcetypes coming to Splunk from udp:514. ... by alextsui Path Finder in Getting Data In 07-28-2010 0 3 | 0 | 3 | ||
| I see the BIG-IP can send syslog for administrative activity. I want to send syslog for all the HTTP requests the loa... by Dan Splunk Employee 4 3 | 4 | 3 | ||
| I am running a pretty basic search such as this email="someemail@domain.com" OR email="someemail@domain.com" ... by Chris_R_ Splunk Employee 1 2 | 1 | 2 | ||
| I think I found the answer to my question when I was writing it. From http://www.splunk.com/base/Documentation/4.1/A... by Joffer Path Finder in Getting Data In 07-27-2010 0 2 | 0 | 2 | ||
| Hi folks, as DHCP logfiles contain huge headers, with always the same information, i will remove them, befor indexin... by simuvid Splunk Employee 2 2 | 2 | 2 | ||
| Hi, Just to check, I've a splunk forwarder that shows lesser events indexed than on the splunk indexer.Is it suppose... by remy06 Contributor in Getting Data In 07-27-2010 0 1 | 0 | 1 | ||
| When monitoring an EMC Clarion, the CLI tool to dump the logs simply dumps all logs from the device, including any pr... by Ron_Naken Splunk Employee 3 1 | 3 | 1 | ||
| I'm trying to enable SSO by proxying from Apache w/ mod_auth_kerb. The problems seems to be the contents of Remote-Us... by dmesler Explorer in Getting Data In 07-26-2010 2 2 | 2 | 2 |