Getting Data In

Getting Data In
Community Activity
Jaci
I have a deployment server app with a single inputs.conf file. [tcp://localhost:9997] sourcetype = tcp-raw index = p...
by Jaci Splunk Employee Splunk Employee in Getting Data In 05-24-2010
1 2
1
2
jeff
I have the following in inputs.conf: [udp://32004] host = custom_host connection_host = non...
by jeff Contributor in Getting Data In 05-22-2010
3 3
3
3
mctester
Hi, I have a development support question. We have an application that is integrated with splunk. We have a C++ p...
by mctester Communicator in Getting Data In 05-22-2010
2 1
2
1
dcroteau
we only want to save the log info for 2 weeks. I tried to set this up by modifying the frozen time, but it doesn’t s...
by dcroteau Splunk Employee Splunk Employee in Getting Data In 05-22-2010
1 3
1
3
maverick
Suppose I splunk a file and it is gzip'd on disk under the appropriate Splunk index directory. Then let's say I con...
by maverick Splunk Employee Splunk Employee in Getting Data In 05-22-2010
1 1
1
1
Genti
Forwarding a question: "... attempting to setup a lookup table. Each time I save an automatic lookup it always retur...
by Genti Splunk Employee Splunk Employee in Getting Data In 05-21-2010
0 1
0
1
Justin_Grant
If our app's inputs.conf uses an index other than "main" (e.g. a custom index for our app) does our app's setup UI (o...
by Justin_Grant Contributor in Getting Data In 05-21-2010
1 5
1
5
Jaci
Does a forwarder keep using the initial TCP connection to the indexing server, or does it close the connection after ...
by Jaci Splunk Employee Splunk Employee in Getting Data In 05-21-2010
2 1
2
1
return2health
Hi there. I'm new to splunk. Having a bit of trouble getting my head around it ( I know SQL well ) . I want to get...
by return2health Engager in Getting Data In 05-21-2010
1 2
1
2
Nicholas_Key
I am perplexed with what I'm experiencing right now. I have all the file inputs enabled for monitor but I'm not seei...
by Nicholas_Key Splunk Employee Splunk Employee in Getting Data In 05-21-2010
1 2
1
2
Jaci
I monitor a log file (access_log) that gets rolled every night at 1 am using a copy command "cp /dev/null access_toda...
by Jaci Splunk Employee Splunk Employee in Getting Data In 05-20-2010
1 3
1
3
jwestberg
I am creating an app for Splunk 4.1 that has a scripted input that retrieves data from a database. At first run, it w...
by jwestberg Splunk Employee Splunk Employee in Getting Data In 05-20-2010
2 5
2
5
phoenixsecure
Hi, I am collecting event logs thru WMI for Windows 2000 and 2003 servers, for 2003 everything seem ok but for 2000 ...
by phoenixsecure Engager in Getting Data In 05-20-2010
2 2
2
2
Chris_R_
How do keep splunk from removing syslog priority fields? They are removed once indexed into splunk.
by Chris_R_ Splunk Employee Splunk Employee in Getting Data In 05-19-2010
0 3
0
3
Yancy
Since I updated our server to 4.1.2 I'm seeing the following error with most searches. The lookup table 'sid_look...
by Yancy Path Finder in Getting Data In 05-19-2010
2 2
2
2
carmackd
Can I use blacklist in a batch stanza? I couldn't find anything in the documentation saying otherwise. Thanks,
by carmackd Communicator in Getting Data In 05-19-2010
2 2
2
2
djfisher
I use the recommended search below to find lost forwarders after a 24hr period. http://www.splunk.com/wiki/Depl...
by djfisher Explorer in Getting Data In 05-19-2010
1 5
1
5
oreoshake
I'm starting to get a lot of these errors on my forwarders. Any suggestions? Pushing /etc/security/limits.conf does...
by oreoshake Communicator in Getting Data In 05-19-2010
0 2
0
2
seanlon11
How can I easily search through Splunk to figure out which sources are associated with a specific host? I know I c...
by seanlon11 Path Finder in Getting Data In 05-19-2010
1 2
1
2
oreoshake
We are using "heavy" forwarders, but I have the following config on both the forwarder and the indexer but the events...
by oreoshake Communicator in Getting Data In 05-18-2010
1 4
1
4
piebob
reposting for a user over on the forums: I bounced my indexer and now my forwarders are unable to connect. I just u...
by piebob Splunk Employee Splunk Employee in Getting Data In 05-18-2010
1 2
1
2
Lowell
I am having trouble getting _internal and _audit to be forwarder properly when being passed through more than one for...
by Lowell Super Champion in Getting Data In 05-17-2010
1 6
1
6
petru
Hello I have a question about splunk capabilities. I installed splunk on a server (domain member) and I can get th...
by petru Engager in Getting Data In 05-17-2010
1 1
1
1
craigallen
Hi, We have installed Splunk under an eval using just a local username. We'd like to monitor AD, but can't work out ...
by craigallen Engager in Getting Data In 05-17-2010
1 1
1
1
msallman
We are having a problem getting the Windows app to display wmi data. It seems that the wmi data we are getting is bei...
by msallman Explorer in Getting Data In 05-14-2010
0 7
0
7
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...
Top Solution Authors