Getting Data In

Getting Data In
Community Activity
AthlonRob
Is it possible to somehow configure the "default" index on a per-host basis? We have several lightweight forwarders ...
by AthlonRob Engager in Getting Data In 05-05-2010
1 1
1
1
clyde772
Would I be able to rename a "Source Type" after the data got already indexed into Splunk? Can I rename a type of pat...
by clyde772 Communicator in Getting Data In 05-05-2010
1 2
1
2
mkinner
I recently upgraded to 4.1.2 from 3.4.x. I needed to remove several hosts from our index, so I followed the instruct...
by mkinner Explorer in Getting Data In 05-04-2010
1 2
1
2
clyde772
It it possible to get the result of current splunk index to a new index files as a new source type? [ Already indexe...
by clyde772 Communicator in Getting Data In 05-04-2010
0 3
0
3
cdavidy
My Splunk server is listening to UDP port 514 for syslog information. How can I route data to a given index based on...
by cdavidy Explorer in Getting Data In 05-03-2010
0 1
0
1
clyde772
1
1
clyde772
I have seen manytime where Splunk didn't copped either multi or single line data correctly ending up with events that...
by clyde772 Communicator in Getting Data In 05-01-2010
0 1
0
1
Ron_Naken
I have an ISA web log of the following format. Splunk doesn't correctly identify the timestamp in every event, even ...
by Ron_Naken Splunk Employee Splunk Employee in Getting Data In 04-30-2010
4 2
4
2
jbidinger
I am trying to implement file integrity monitoring. I have configured fschange as follows: [fschange:/opt/bea/10_sp0...
by jbidinger Explorer in Getting Data In 04-30-2010
0 6
0
6
micropotato
I see the same host in my Summary page in Search app with same event count. They are the same host but show up like:...
by micropotato Engager in Getting Data In 04-30-2010
1 1
1
1
Simon
Hi everybody At the moment I've got about 170 indexes on my indexer. I What's the best practice limit of numbers of...
by Simon Contributor in Getting Data In 04-29-2010
0 2
0
2
Lowell
Can someone shed light on the purpose of the _s _st and _h indexed fields? These seem to correspond to source, sourc...
by Lowell Super Champion in Getting Data In 04-29-2010
0 2
0
2
maverick
Regarding agent vs agentless data / event gatering, WMI (agentless) seems easier to setup from within Splunk to pull ...
by maverick Splunk Employee Splunk Employee in Getting Data In 04-28-2010
1 2
1
2
muebel
My indexer has a Intel Xeon X5570 which has four cores. http://ark.intel.com/Product.aspx?id=37111 How can I make s...
by SplunkTrust SplunkTrust in Getting Data In 04-27-2010
1 1
1
1
bc_unixadm
How can I tell which servers in my enterprise are forwarding to the master server. We do automated installs of vm's a...
by bc_unixadm Explorer in Getting Data In 04-27-2010
1 5
1
5
maverick
Can Splunk index events from my Checkpoint firewall logs? If so, how can I set that up?
by maverick Splunk Employee Splunk Employee in Getting Data In 04-27-2010
1 4
1
4
jradkowskiAAMC
Currently, all agents installed on hosts default to 'changeme' and this credential is still used when the forwarder i...
by jradkowskiAAMC Explorer in Getting Data In 04-26-2010
0 2
0
2
sivakumar_inbox
I had configured splunk forwarder and receiver in a Linux system as per the Admin manual. I tried searching the forwa...
by sivakumar_inbox Engager in Getting Data In 04-26-2010
1 2
1
2
cpenkert
We are on 4.05 and are using the default of memPoolMB = auto in indexes.conf. Is there a way I can find out what size...
by cpenkert Path Finder in Getting Data In 04-24-2010
1 5
1
5
SK110176
Referenced Doc: http://www.splunk.com/base/Documentation/4.1/Admin/Moreaboutforwarders I need to be able to send da...
by SK110176 Path Finder in Getting Data In 04-24-2010
1 4
1
4
Jaci
I've verified that the indexer (receiver) is the same or later version of Splunk as the forwarder. What log or config...
by Jaci Splunk Employee Splunk Employee in Getting Data In 04-23-2010
4 6
4
6
tpaulsen
We have on four Linux SLES10_64 Servers Splunk 3.4.4. Forwarders installed. Usually our production logs produce a con...
by tpaulsen Contributor in Getting Data In 04-23-2010
0 1
0
1
Alan_Bradley
I have one splunk forwarder I need to segregate from other indexes. I have created its own index and I need to know h...
by Alan_Bradley Path Finder in Getting Data In 04-23-2010
1 2
1
2
mctester
Currently, when I try to run a search in Splunk, I get the following error message: "Error in 'UnifiedSearch': You...
by mctester Communicator in Getting Data In 04-22-2010
1 1
1
1
tpaulsen
Hello, i want to collect logs from one forwarder (Splunk 4.0.10) and forward the data to different indexes on one in...
by tpaulsen Contributor in Getting Data In 04-22-2010
1 7
1
7
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...