Getting Data In

Getting Data In
Community Activity
cdavidy
My Splunk server is listening to UDP port 514 for syslog information. How can I route data to a given index based on...
by cdavidy Explorer in Getting Data In 05-03-2010
0 1
0
1
clyde772
1
1
clyde772
I have seen manytime where Splunk didn't copped either multi or single line data correctly ending up with events that...
by clyde772 Communicator in Getting Data In 05-01-2010
0 1
0
1
Ron_Naken
I have an ISA web log of the following format. Splunk doesn't correctly identify the timestamp in every event, even ...
by Ron_Naken Splunk Employee Splunk Employee in Getting Data In 04-30-2010
4 2
4
2
jbidinger
I am trying to implement file integrity monitoring. I have configured fschange as follows: [fschange:/opt/bea/10_sp0...
by jbidinger Explorer in Getting Data In 04-30-2010
0 6
0
6
micropotato
I see the same host in my Summary page in Search app with same event count. They are the same host but show up like:...
by micropotato Engager in Getting Data In 04-30-2010
1 1
1
1
Simon
Hi everybody At the moment I've got about 170 indexes on my indexer. I What's the best practice limit of numbers of...
by Simon Contributor in Getting Data In 04-29-2010
0 2
0
2
Lowell
Can someone shed light on the purpose of the _s _st and _h indexed fields? These seem to correspond to source, sourc...
by Lowell Super Champion in Getting Data In 04-29-2010
0 2
0
2
maverick
Regarding agent vs agentless data / event gatering, WMI (agentless) seems easier to setup from within Splunk to pull ...
by maverick Splunk Employee Splunk Employee in Getting Data In 04-28-2010
1 2
1
2
muebel
My indexer has a Intel Xeon X5570 which has four cores. http://ark.intel.com/Product.aspx?id=37111 How can I make s...
by SplunkTrust SplunkTrust in Getting Data In 04-27-2010
1 1
1
1
bc_unixadm
How can I tell which servers in my enterprise are forwarding to the master server. We do automated installs of vm's a...
by bc_unixadm Explorer in Getting Data In 04-27-2010
1 5
1
5
maverick
Can Splunk index events from my Checkpoint firewall logs? If so, how can I set that up?
by maverick Splunk Employee Splunk Employee in Getting Data In 04-27-2010
1 4
1
4
jradkowskiAAMC
Currently, all agents installed on hosts default to 'changeme' and this credential is still used when the forwarder i...
by jradkowskiAAMC Explorer in Getting Data In 04-26-2010
0 2
0
2
sivakumar_inbox
I had configured splunk forwarder and receiver in a Linux system as per the Admin manual. I tried searching the forwa...
by sivakumar_inbox Engager in Getting Data In 04-26-2010
1 2
1
2
cpenkert
We are on 4.05 and are using the default of memPoolMB = auto in indexes.conf. Is there a way I can find out what size...
by cpenkert Path Finder in Getting Data In 04-24-2010
1 5
1
5
SK110176
Referenced Doc: http://www.splunk.com/base/Documentation/4.1/Admin/Moreaboutforwarders I need to be able to send da...
by SK110176 Path Finder in Getting Data In 04-24-2010
1 4
1
4
Jaci
I've verified that the indexer (receiver) is the same or later version of Splunk as the forwarder. What log or config...
by Jaci Splunk Employee Splunk Employee in Getting Data In 04-23-2010
4 6
4
6
tpaulsen
We have on four Linux SLES10_64 Servers Splunk 3.4.4. Forwarders installed. Usually our production logs produce a con...
by tpaulsen Contributor in Getting Data In 04-23-2010
0 1
0
1
Alan_Bradley
I have one splunk forwarder I need to segregate from other indexes. I have created its own index and I need to know h...
by Alan_Bradley Path Finder in Getting Data In 04-23-2010
1 2
1
2
mctester
Currently, when I try to run a search in Splunk, I get the following error message: "Error in 'UnifiedSearch': You...
by mctester Communicator in Getting Data In 04-22-2010
1 1
1
1
tpaulsen
Hello, i want to collect logs from one forwarder (Splunk 4.0.10) and forward the data to different indexes on one in...
by tpaulsen Contributor in Getting Data In 04-22-2010
1 7
1
7
tier2ops
This has happened twice so far in a week. Users begin contacting me that they are unable to log in. Both times I ra...
by tier2ops Explorer in Getting Data In 04-21-2010
1 6
1
6
alextsui
Hello, when using the following setup in props.conf, i was able to get the sourcetypes I want. [source::/var/splunk/...
by alextsui Path Finder in Getting Data In 04-21-2010
2 1
2
1
jheilman
I have a set of logs that no longer appear to be being indexed. I had originally configured the monitor as follows......
by jheilman Explorer in Getting Data In 04-21-2010
0 2
0
2
rbruno7
Hi Guys, We have built a small Splunk app to retrieve and index web usage info from multiple SQL databases. My Splun...
by rbruno7 Explorer in Getting Data In 04-21-2010
0 6
0
6
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors