Getting Data In

Getting Data In
Community Activity
Lowell
I am having trouble getting _internal and _audit to be forwarder properly when being passed through more than one for...
by Lowell Super Champion in Getting Data In 05-17-2010
1 6
1
6
petru
Hello I have a question about splunk capabilities. I installed splunk on a server (domain member) and I can get th...
by petru Engager in Getting Data In 05-17-2010
1 1
1
1
craigallen
Hi, We have installed Splunk under an eval using just a local username. We'd like to monitor AD, but can't work out ...
by craigallen Engager in Getting Data In 05-17-2010
1 1
1
1
msallman
We are having a problem getting the Windows app to display wmi data. It seems that the wmi data we are getting is bei...
by msallman Explorer in Getting Data In 05-14-2010
0 7
0
7
Dan
On Splunk 4.1, I see a bunch of these messages. What do they mean? Should I be concerned? 04-28-2010 13:48:32.27...
by Dan Splunk Employee Splunk Employee in Getting Data In 05-13-2010
2 3
2
3
gljiva
Hi, i saw many suggestions to routing data to different index from light forwarder but none seems to work. I have se...
by gljiva Path Finder in Getting Data In 05-12-2010
3 5
3
5
ericmoss
I am trying to forward event logs from a Windows XP machine to a Windows 2003 machine. I set up Splunk on the Window...
by ericmoss Explorer in Getting Data In 05-12-2010
1 1
1
1
geva
Hey all: I'm very interested in setting Splunk up to have it monitor all of my logs. One of such main requirements ...
by geva Explorer in Getting Data In 05-12-2010
2 10
2
10
clyde772
I have changed input.conf and restarted Spulnk, but I can't see any event generated for changing /etc/hosts file. Th...
by clyde772 Communicator in Getting Data In 05-12-2010
3 2
3
2
rgonzale6
What I'd like is to have the date appended to the file name. Currently we have a scheduled saved search running each...
by rgonzale6 Path Finder in Getting Data In 05-11-2010
0 3
0
3
MikeyG
Can't find a reference to the following error. What does it mean and how do I fix it? Indexing Significant Warns: W...
by MikeyG Explorer in Getting Data In 05-11-2010
1 4
1
4
MU_IT
I would like to aggregate data from my NPS servers for helpdesk/support use. I have set up a custom index on each se...
by MU_IT New Member in Getting Data In 05-10-2010
0 1
0
1
sipapress2go
How do I secure my log file stream from our primary server to our dedicated Splunk server? Are there any secured laye...
by sipapress2go Engager in Getting Data In 05-10-2010
1 7
1
7
ravi_shah01
Hi, I have a requirement to extract all the events in a file. Example: For an order number, there are around 100 e...
by ravi_shah01 Engager in Getting Data In 05-10-2010
0 2
0
2
vbumgarn
Is there any way to prepopulate the Time Picker via a URL parameter? I need to build a search dynamically in an exte...
by vbumgarn Path Finder in Getting Data In 05-08-2010
2 3
2
3
jeff
Windows Server 2008 R2 x64 (Windows AD Domain Controller) / Splunk 4.1.1 set up as a full forwarder (custom app via d...
by jeff Contributor in Getting Data In 05-07-2010
1 4
1
4
hans
Here is a sample log: 2010-05-06 16:41:18,082 INFO SplunkCLI :: Executing: "/Users/hs/bin/" status space Th...
by hans Splunk Employee Splunk Employee in Getting Data In 05-07-2010
0 2
0
2
Justin_Grant
We're building an app for WebSphere. We're prefixing all the app's sourcetypes with "WebSphere:" to disambiguate them...
by Justin_Grant Contributor in Getting Data In 05-07-2010
1 1
1
1
chris
Hi We recently had a problem with one type of our indexed log files suddenly being recognized as binary. This is t...
by chris Motivator in Getting Data In 05-06-2010
1 4
1
4
kevintelford
So, say we had a dataset with 5 fields, 20 trillion rows. I assume the csv file would be smaller when indexed, but...
by kevintelford Path Finder in Getting Data In 05-05-2010
1 8
1
8
AthlonRob
Is it possible to somehow configure the "default" index on a per-host basis? We have several lightweight forwarders ...
by AthlonRob Engager in Getting Data In 05-05-2010
1 1
1
1
clyde772
Would I be able to rename a "Source Type" after the data got already indexed into Splunk? Can I rename a type of pat...
by clyde772 Communicator in Getting Data In 05-05-2010
1 2
1
2
mkinner
I recently upgraded to 4.1.2 from 3.4.x. I needed to remove several hosts from our index, so I followed the instruct...
by mkinner Explorer in Getting Data In 05-04-2010
1 2
1
2
clyde772
It it possible to get the result of current splunk index to a new index files as a new source type? [ Already indexe...
by clyde772 Communicator in Getting Data In 05-04-2010
0 3
0
3
cdavidy
My Splunk server is listening to UDP port 514 for syslog information. How can I route data to a given index based on...
by cdavidy Explorer in Getting Data In 05-03-2010
0 1
0
1
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors