Getting Data In

Getting Data In
Community Activity
Genti
What is the relationship between size of logs received by Splunk indexing servers versus indexing volume? On the load...
by Genti Splunk Employee Splunk Employee in Getting Data In 05-24-2010
0 1
0
1
Jaci
I have a deployment server app with a single inputs.conf file. [tcp://localhost:9997] sourcetype = tcp-raw index = p...
by Jaci Splunk Employee Splunk Employee in Getting Data In 05-24-2010
1 2
1
2
jeff
I have the following in inputs.conf: [udp://32004] host = custom_host connection_host = non...
by jeff Contributor in Getting Data In 05-22-2010
3 3
3
3
mctester
Hi, I have a development support question. We have an application that is integrated with splunk. We have a C++ p...
by mctester Communicator in Getting Data In 05-22-2010
2 1
2
1
dcroteau
we only want to save the log info for 2 weeks. I tried to set this up by modifying the frozen time, but it doesn’t s...
by dcroteau Splunk Employee Splunk Employee in Getting Data In 05-22-2010
1 3
1
3
maverick
Suppose I splunk a file and it is gzip'd on disk under the appropriate Splunk index directory. Then let's say I con...
by maverick Splunk Employee Splunk Employee in Getting Data In 05-22-2010
1 1
1
1
Genti
Forwarding a question: "... attempting to setup a lookup table. Each time I save an automatic lookup it always retur...
by Genti Splunk Employee Splunk Employee in Getting Data In 05-21-2010
0 1
0
1
Justin_Grant
If our app's inputs.conf uses an index other than "main" (e.g. a custom index for our app) does our app's setup UI (o...
by Justin_Grant Contributor in Getting Data In 05-21-2010
1 5
1
5
Jaci
Does a forwarder keep using the initial TCP connection to the indexing server, or does it close the connection after ...
by Jaci Splunk Employee Splunk Employee in Getting Data In 05-21-2010
2 1
2
1
return2health
Hi there. I'm new to splunk. Having a bit of trouble getting my head around it ( I know SQL well ) . I want to get...
by return2health Engager in Getting Data In 05-21-2010
1 2
1
2
Nicholas_Key
I am perplexed with what I'm experiencing right now. I have all the file inputs enabled for monitor but I'm not seei...
by Nicholas_Key Splunk Employee Splunk Employee in Getting Data In 05-21-2010
1 2
1
2
Jaci
I monitor a log file (access_log) that gets rolled every night at 1 am using a copy command "cp /dev/null access_toda...
by Jaci Splunk Employee Splunk Employee in Getting Data In 05-20-2010
1 3
1
3
jwestberg
I am creating an app for Splunk 4.1 that has a scripted input that retrieves data from a database. At first run, it w...
by jwestberg Splunk Employee Splunk Employee in Getting Data In 05-20-2010
2 5
2
5
phoenixsecure
Hi, I am collecting event logs thru WMI for Windows 2000 and 2003 servers, for 2003 everything seem ok but for 2000 ...
by phoenixsecure Engager in Getting Data In 05-20-2010
2 2
2
2
Chris_R_
How do keep splunk from removing syslog priority fields? They are removed once indexed into splunk.
by Chris_R_ Splunk Employee Splunk Employee in Getting Data In 05-19-2010
0 3
0
3
Yancy
Since I updated our server to 4.1.2 I'm seeing the following error with most searches. The lookup table 'sid_look...
by Yancy Path Finder in Getting Data In 05-19-2010
2 2
2
2
carmackd
Can I use blacklist in a batch stanza? I couldn't find anything in the documentation saying otherwise. Thanks,
by carmackd Communicator in Getting Data In 05-19-2010
2 2
2
2
djfisher
I use the recommended search below to find lost forwarders after a 24hr period. http://www.splunk.com/wiki/Depl...
by djfisher Explorer in Getting Data In 05-19-2010
1 5
1
5
oreoshake
I'm starting to get a lot of these errors on my forwarders. Any suggestions? Pushing /etc/security/limits.conf does...
by oreoshake Communicator in Getting Data In 05-19-2010
0 2
0
2
seanlon11
How can I easily search through Splunk to figure out which sources are associated with a specific host? I know I c...
by seanlon11 Path Finder in Getting Data In 05-19-2010
1 2
1
2
oreoshake
We are using "heavy" forwarders, but I have the following config on both the forwarder and the indexer but the events...
by oreoshake Communicator in Getting Data In 05-18-2010
1 4
1
4
piebob
reposting for a user over on the forums: I bounced my indexer and now my forwarders are unable to connect. I just u...
by piebob Splunk Employee Splunk Employee in Getting Data In 05-18-2010
1 2
1
2
Lowell
I am having trouble getting _internal and _audit to be forwarder properly when being passed through more than one for...
by Lowell Super Champion in Getting Data In 05-17-2010
1 6
1
6
petru
Hello I have a question about splunk capabilities. I installed splunk on a server (domain member) and I can get th...
by petru Engager in Getting Data In 05-17-2010
1 1
1
1
craigallen
Hi, We have installed Splunk under an eval using just a local username. We'd like to monitor AD, but can't work out ...
by craigallen Engager in Getting Data In 05-17-2010
1 1
1
1
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...
Top Solution Authors