| Is it possible to somehow configure the "default" index on a per-host basis? We have several lightweight forwarders ... by AthlonRob Engager in Getting Data In 05-05-2010 1 1 | 1 | 1 | ||
| Would I be able to rename a "Source Type" after the data got already indexed into Splunk? Can I rename a type of pat... by clyde772 Communicator in Getting Data In 05-05-2010 1 2 | 1 | 2 | ||
| I recently upgraded to 4.1.2 from 3.4.x. I needed to remove several hosts from our index, so I followed the instruct... by mkinner Explorer in Getting Data In 05-04-2010 1 2 | 1 | 2 | ||
| It it possible to get the result of current splunk index to a new index files as a new source type? [ Already indexe... by clyde772 Communicator in Getting Data In 05-04-2010 0 3 | 0 | 3 | ||
| My Splunk server is listening to UDP port 514 for syslog information. How can I route data to a given index based on... by cdavidy Explorer in Getting Data In 05-03-2010 0 1 | 0 | 1 | ||
| Instead of file being appended, if the file gets overwritted or rewrited, does splunk re-evaluates the entire file da... by clyde772 Communicator in Getting Data In 05-02-2010 1 1 | 1 | 1 | ||
| I have seen manytime where Splunk didn't copped either multi or single line data correctly ending up with events that... by clyde772 Communicator in Getting Data In 05-01-2010 0 1 | 0 | 1 | ||
| I have an ISA web log of the following format. Splunk doesn't correctly identify the timestamp in every event, even ... by Ron_Naken Splunk Employee 4 2 | 4 | 2 | ||
| I am trying to implement file integrity monitoring. I have configured fschange as follows: [fschange:/opt/bea/10_sp0... by jbidinger Explorer in Getting Data In 04-30-2010 0 6 | 0 | 6 | ||
| I see the same host in my Summary page in Search app with same event count. They are the same host but show up like:... by micropotato Engager in Getting Data In 04-30-2010 1 1 | 1 | 1 | ||
| Hi everybody At the moment I've got about 170 indexes on my indexer. I What's the best practice limit of numbers of... by Simon Contributor in Getting Data In 04-29-2010 0 2 | 0 | 2 | ||
| Can someone shed light on the purpose of the _s _st and _h indexed fields? These seem to correspond to source, sourc... by Lowell Super Champion in Getting Data In 04-29-2010 0 2 | 0 | 2 | ||
| Regarding agent vs agentless data / event gatering, WMI (agentless) seems easier to setup from within Splunk to pull ... by maverick Splunk Employee 1 2 | 1 | 2 | ||
| My indexer has a Intel Xeon X5570 which has four cores. http://ark.intel.com/Product.aspx?id=37111 How can I make s... by muebel SplunkTrust 1 1 | 1 | 1 | ||
| How can I tell which servers in my enterprise are forwarding to the master server. We do automated installs of vm's a... by bc_unixadm Explorer in Getting Data In 04-27-2010 1 5 | 1 | 5 | ||
| Can Splunk index events from my Checkpoint firewall logs? If so, how can I set that up? by maverick Splunk Employee 1 4 | 1 | 4 | ||
| Currently, all agents installed on hosts default to 'changeme' and this credential is still used when the forwarder i... by jradkowskiAAMC Explorer in Getting Data In 04-26-2010 0 2 | 0 | 2 | ||
| I had configured splunk forwarder and receiver in a Linux system as per the Admin manual. I tried searching the forwa... by sivakumar_inbox Engager in Getting Data In 04-26-2010 1 2 | 1 | 2 | ||
| We are on 4.05 and are using the default of memPoolMB = auto in indexes.conf. Is there a way I can find out what size... by cpenkert Path Finder in Getting Data In 04-24-2010 1 5 | 1 | 5 | ||
| Referenced Doc: http://www.splunk.com/base/Documentation/4.1/Admin/Moreaboutforwarders I need to be able to send da... by SK110176 Path Finder in Getting Data In 04-24-2010 1 4 | 1 | 4 | ||
| I've verified that the indexer (receiver) is the same or later version of Splunk as the forwarder. What log or config... by Jaci Splunk Employee 4 6 | 4 | 6 | ||
| We have on four Linux SLES10_64 Servers Splunk 3.4.4. Forwarders installed. Usually our production logs produce a con... by tpaulsen Contributor in Getting Data In 04-23-2010 0 1 | 0 | 1 | ||
| I have one splunk forwarder I need to segregate from other indexes. I have created its own index and I need to know h... by Alan_Bradley Path Finder in Getting Data In 04-23-2010 1 2 | 1 | 2 | ||
| Currently, when I try to run a search in Splunk, I get the following error message: "Error in 'UnifiedSearch': You... by mctester Communicator in Getting Data In 04-22-2010 1 1 | 1 | 1 | ||
| Hello, i want to collect logs from one forwarder (Splunk 4.0.10) and forward the data to different indexes on one in... by tpaulsen Contributor in Getting Data In 04-22-2010 1 7 | 1 | 7 |