Getting Data In

Getting Data In
Community Activity
Jaci
I monitor a log file (access_log) that gets rolled every night at 1 am using a copy command "cp /dev/null access_toda...
by Jaci Splunk Employee Splunk Employee in Getting Data In 05-20-2010
1 3
1
3
jwestberg
I am creating an app for Splunk 4.1 that has a scripted input that retrieves data from a database. At first run, it w...
by jwestberg Splunk Employee Splunk Employee in Getting Data In 05-20-2010
2 5
2
5
phoenixsecure
Hi, I am collecting event logs thru WMI for Windows 2000 and 2003 servers, for 2003 everything seem ok but for 2000 ...
by phoenixsecure Engager in Getting Data In 05-20-2010
2 2
2
2
Chris_R_
How do keep splunk from removing syslog priority fields? They are removed once indexed into splunk.
by Chris_R_ Splunk Employee Splunk Employee in Getting Data In 05-19-2010
0 3
0
3
Yancy
Since I updated our server to 4.1.2 I'm seeing the following error with most searches. The lookup table 'sid_look...
by Yancy Path Finder in Getting Data In 05-19-2010
2 2
2
2
carmackd
Can I use blacklist in a batch stanza? I couldn't find anything in the documentation saying otherwise. Thanks,
by carmackd Communicator in Getting Data In 05-19-2010
2 2
2
2
djfisher
I use the recommended search below to find lost forwarders after a 24hr period. http://www.splunk.com/wiki/Depl...
by djfisher Explorer in Getting Data In 05-19-2010
1 5
1
5
oreoshake
I'm starting to get a lot of these errors on my forwarders. Any suggestions? Pushing /etc/security/limits.conf does...
by oreoshake Communicator in Getting Data In 05-19-2010
0 2
0
2
seanlon11
How can I easily search through Splunk to figure out which sources are associated with a specific host? I know I c...
by seanlon11 Path Finder in Getting Data In 05-19-2010
1 2
1
2
oreoshake
We are using "heavy" forwarders, but I have the following config on both the forwarder and the indexer but the events...
by oreoshake Communicator in Getting Data In 05-18-2010
1 4
1
4
piebob
reposting for a user over on the forums: I bounced my indexer and now my forwarders are unable to connect. I just u...
by piebob Splunk Employee Splunk Employee in Getting Data In 05-18-2010
1 2
1
2
Lowell
I am having trouble getting _internal and _audit to be forwarder properly when being passed through more than one for...
by Lowell Super Champion in Getting Data In 05-17-2010
1 6
1
6
petru
Hello I have a question about splunk capabilities. I installed splunk on a server (domain member) and I can get th...
by petru Engager in Getting Data In 05-17-2010
1 1
1
1
craigallen
Hi, We have installed Splunk under an eval using just a local username. We'd like to monitor AD, but can't work out ...
by craigallen Engager in Getting Data In 05-17-2010
1 1
1
1
msallman
We are having a problem getting the Windows app to display wmi data. It seems that the wmi data we are getting is bei...
by msallman Explorer in Getting Data In 05-14-2010
0 7
0
7
Dan
On Splunk 4.1, I see a bunch of these messages. What do they mean? Should I be concerned? 04-28-2010 13:48:32.27...
by Dan Splunk Employee Splunk Employee in Getting Data In 05-13-2010
2 3
2
3
gljiva
Hi, i saw many suggestions to routing data to different index from light forwarder but none seems to work. I have se...
by gljiva Path Finder in Getting Data In 05-12-2010
3 5
3
5
ericmoss
I am trying to forward event logs from a Windows XP machine to a Windows 2003 machine. I set up Splunk on the Window...
by ericmoss Explorer in Getting Data In 05-12-2010
1 1
1
1
geva
Hey all: I'm very interested in setting Splunk up to have it monitor all of my logs. One of such main requirements ...
by geva Explorer in Getting Data In 05-12-2010
2 10
2
10
clyde772
I have changed input.conf and restarted Spulnk, but I can't see any event generated for changing /etc/hosts file. Th...
by clyde772 Communicator in Getting Data In 05-12-2010
3 2
3
2
rgonzale6
What I'd like is to have the date appended to the file name. Currently we have a scheduled saved search running each...
by rgonzale6 Path Finder in Getting Data In 05-11-2010
0 3
0
3
MikeyG
Can't find a reference to the following error. What does it mean and how do I fix it? Indexing Significant Warns: W...
by MikeyG Explorer in Getting Data In 05-11-2010
1 4
1
4
MU_IT
I would like to aggregate data from my NPS servers for helpdesk/support use. I have set up a custom index on each se...
by MU_IT New Member in Getting Data In 05-10-2010
0 1
0
1
sipapress2go
How do I secure my log file stream from our primary server to our dedicated Splunk server? Are there any secured laye...
by sipapress2go Engager in Getting Data In 05-10-2010
1 7
1
7
ravi_shah01
Hi, I have a requirement to extract all the events in a file. Example: For an order number, there are around 100 e...
by ravi_shah01 Engager in Getting Data In 05-10-2010
0 2
0
2
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Solution Authors