| I have a deployment server app with a single inputs.conf file. [tcp://localhost:9997] sourcetype = tcp-raw index = p... by Jaci Splunk Employee 1 2 | 1 | 2 | ||
| I have the following in inputs.conf: [udp://32004] host = custom_host connection_host = non... by jeff Contributor in Getting Data In 05-22-2010 3 3 | 3 | 3 | ||
| Hi, I have a development support question. We have an application that is integrated with splunk. We have a C++ p... by mctester Communicator in Getting Data In 05-22-2010 2 1 | 2 | 1 | ||
| we only want to save the log info for 2 weeks. I tried to set this up by modifying the frozen time, but it doesn’t s... by dcroteau Splunk Employee 1 3 | 1 | 3 | ||
| Suppose I splunk a file and it is gzip'd on disk under the appropriate Splunk index directory. Then let's say I con... by maverick Splunk Employee 1 1 | 1 | 1 | ||
| Forwarding a question: "... attempting to setup a lookup table. Each time I save an automatic lookup it always retur... by Genti Splunk Employee 0 1 | 0 | 1 | ||
| If our app's inputs.conf uses an index other than "main" (e.g. a custom index for our app) does our app's setup UI (o... by Justin_Grant Contributor in Getting Data In 05-21-2010 1 5 | 1 | 5 | ||
| Does a forwarder keep using the initial TCP connection to the indexing server, or does it close the connection after ... by Jaci Splunk Employee 2 1 | 2 | 1 | ||
| Hi there. I'm new to splunk. Having a bit of trouble getting my head around it ( I know SQL well ) . I want to get... by return2health Engager in Getting Data In 05-21-2010 1 2 | 1 | 2 | ||
| I am perplexed with what I'm experiencing right now. I have all the file inputs enabled for monitor but I'm not seei... by Nicholas_Key Splunk Employee 1 2 | 1 | 2 | ||
| I monitor a log file (access_log) that gets rolled every night at 1 am using a copy command "cp /dev/null access_toda... by Jaci Splunk Employee 1 3 | 1 | 3 | ||
| I am creating an app for Splunk 4.1 that has a scripted input that retrieves data from a database. At first run, it w... by jwestberg Splunk Employee 2 5 | 2 | 5 | ||
| Hi, I am collecting event logs thru WMI for Windows 2000 and 2003 servers, for 2003 everything seem ok but for 2000 ... by phoenixsecure Engager in Getting Data In 05-20-2010 2 2 | 2 | 2 | ||
| How do keep splunk from removing syslog priority fields? They are removed once indexed into splunk. by Chris_R_ Splunk Employee 0 3 | 0 | 3 | ||
| Since I updated our server to 4.1.2 I'm seeing the following error with most searches. The lookup table 'sid_look... by Yancy Path Finder in Getting Data In 05-19-2010 2 2 | 2 | 2 | ||
| Can I use blacklist in a batch stanza? I couldn't find anything in the documentation saying otherwise. Thanks, by carmackd Communicator in Getting Data In 05-19-2010 2 2 | 2 | 2 | ||
| I use the recommended search below to find lost forwarders after a 24hr period. http://www.splunk.com/wiki/Depl... by djfisher Explorer in Getting Data In 05-19-2010 1 5 | 1 | 5 | ||
| I'm starting to get a lot of these errors on my forwarders. Any suggestions? Pushing /etc/security/limits.conf does... by oreoshake Communicator in Getting Data In 05-19-2010 0 2 | 0 | 2 | ||
| How can I easily search through Splunk to figure out which sources are associated with a specific host? I know I c... by seanlon11 Path Finder in Getting Data In 05-19-2010 1 2 | 1 | 2 | ||
| We are using "heavy" forwarders, but I have the following config on both the forwarder and the indexer but the events... by oreoshake Communicator in Getting Data In 05-18-2010 1 4 | 1 | 4 | ||
| reposting for a user over on the forums: I bounced my indexer and now my forwarders are unable to connect. I just u... by piebob Splunk Employee 1 2 | 1 | 2 | ||
| I am having trouble getting _internal and _audit to be forwarder properly when being passed through more than one for... by Lowell Super Champion in Getting Data In 05-17-2010 1 6 | 1 | 6 | ||
| Hello I have a question about splunk capabilities. I installed splunk on a server (domain member) and I can get th... by petru Engager in Getting Data In 05-17-2010 1 1 | 1 | 1 | ||
| Hi, We have installed Splunk under an eval using just a local username. We'd like to monitor AD, but can't work out ... by craigallen Engager in Getting Data In 05-17-2010 1 1 | 1 | 1 | ||
| We are having a problem getting the Windows app to display wmi data. It seems that the wmi data we are getting is bei... by msallman Explorer in Getting Data In 05-14-2010 0 7 | 0 | 7 |