Thread Info | |||||
---|---|---|---|---|---|
I recently upgraded to 4.1.2 from 3.4.x. I needed to remove several hosts from our index, so I followed the instructi...
by
mkinner
Explorer
in
Getting Data In
05-03-2010
|
1
|
2
| |||
It it possible to get the result of current splunk index to a new index files as a new source type?
[ Already inde...
by
clyde772
Communicator
in
Getting Data In
05-03-2010
|
0
|
3
| |||
My Splunk server is listening to UDP port 514 for syslog information. How can I route data to a given index based on ...
by
cdavidy
Explorer
in
Getting Data In
05-03-2010
|
0
|
1
| |||
Instead of file being appended, if the file gets overwritted or rewrited, does splunk re-evaluates the entire file da...
by
clyde772
Communicator
in
Getting Data In
05-01-2010
|
1
|
1
| |||
I have seen manytime where Splunk didn't copped either multi or single line data correctly ending up with events that...
by
clyde772
Communicator
in
Getting Data In
05-01-2010
|
0
|
1
| |||
I have an ISA web log of the following format. Splunk doesn't correctly identify the timestamp in every event, even t...
by
Ron_Naken
Splunk Employee
in
Getting Data In
04-30-2010
|
4
|
2
| |||
I am trying to implement file integrity monitoring. I have configured fschange as follows:
[fschange:/opt/bea/10_s...
by
jbidinger
Explorer
in
Getting Data In
04-28-2010
|
0
|
6
| |||
I see the same host in my Summary page in Search app with same event count.
They are the same host but show up lik...
by
micropotato
Engager
in
Getting Data In
04-30-2010
|
1
|
1
| |||
Hi everybody
At the moment I've got about 170 indexes on my indexer. I
What's the best practice limit of number...
by
Simon
Contributor
in
Getting Data In
04-28-2010
|
0
|
2
| |||
Can someone shed light on the purpose of the _s _st and _h indexed fields? These seem to correspond to source, source...
by
Lowell
Super Champion
in
Getting Data In
03-24-2010
|
0
|
2
| |||
Regarding agent vs agentless data / event gatering, WMI (agentless) seems easier to setup from within Splunk to pull ...
by
maverick
Splunk Employee
in
Getting Data In
04-28-2010
|
1
|
2
| |||
My indexer has a Intel Xeon X5570 which has four cores.
http://ark.intel.com/Product.aspx?id=37111
How can I ma...
by
muebel
SplunkTrust
in
Getting Data In
04-27-2010
|
1
|
1
| |||
How can I tell which servers in my enterprise are forwarding to the master server. We do automated installs of vm's a...
by
bc_unixadm
Explorer
in
Getting Data In
04-27-2010
|
1
|
5
| |||
Can Splunk index events from my Checkpoint firewall logs? If so, how can I set that up?
by
maverick
Splunk Employee
in
Getting Data In
03-30-2010
|
1
|
4
| |||
Currently, all agents installed on hosts default to 'changeme' and this credential is still used when the forwarder i...
by
jradkowskiAAMC
Explorer
in
Getting Data In
04-26-2010
|
0
|
2
| |||
I had configured splunk forwarder and receiver in a Linux system as per the Admin manual. I tried searching the forwa...
by
sivakumar_inbox
Engager
in
Getting Data In
04-22-2010
|
1
|
2
| |||
We are on 4.05 and are using the default of memPoolMB = auto in indexes.conf. Is there a way I can find out what size...
by
cpenkert
Path Finder
in
Getting Data In
04-22-2010
|
1
|
5
| |||
Referenced Doc: http://www.splunk.com/base/Documentation/4.1/Admin/Moreaboutforwarders
I need to be able to send d...
by
SK110176
Path Finder
in
Getting Data In
04-19-2010
|
1
|
4
| |||
I've verified that the indexer (receiver) is the same or later version of Splunk as the forwarder. What log or config...
by
Jaci
Splunk Employee
in
Getting Data In
02-19-2010
|
4
|
6
| |||
We have on four Linux SLES10_64 Servers Splunk 3.4.4. Forwarders installed. Usually our production logs produce a con...
by
tpaulsen
Contributor
in
Getting Data In
04-23-2010
|
0
|
1
| |||
I have one splunk forwarder I need to segregate from other indexes. I have created its own index and I need to know h...
by
Alan_Bradley
Path Finder
in
Getting Data In
04-22-2010
|
1
|
2
| |||
Currently, when I try to run a search in Splunk, I get the following error message:
"Error in 'UnifiedSearch': Yo...
by
mctester
Communicator
in
Getting Data In
04-22-2010
|
1
|
1
| |||
Hello,
i want to collect logs from one forwarder (Splunk 4.0.10) and forward the data to different indexes on one ...
by
tpaulsen
Contributor
in
Getting Data In
04-13-2010
|
1
|
7
| |||
This has happened twice so far in a week.
Users begin contacting me that they are unable to log in.
Both times ...
by
tier2ops
Explorer
in
Getting Data In
04-16-2010
|
1
|
6
| |||
Hello, when using the following setup in props.conf, i was able to get the sourcetypes I want.
[source::/var/splun...
by
alextsui
Path Finder
in
Getting Data In
04-21-2010
|
2
|
1
|