Getting Data In

Getting Data In
Community Activity
maverick
Regarding agent vs agentless data / event gatering, WMI (agentless) seems easier to setup from within Splunk to pull ...
by maverick Splunk Employee Splunk Employee in Getting Data In 04-28-2010
1 2
1
2
muebel
My indexer has a Intel Xeon X5570 which has four cores. http://ark.intel.com/Product.aspx?id=37111 How can I make s...
by SplunkTrust SplunkTrust in Getting Data In 04-27-2010
1 1
1
1
bc_unixadm
How can I tell which servers in my enterprise are forwarding to the master server. We do automated installs of vm's a...
by bc_unixadm Explorer in Getting Data In 04-27-2010
1 5
1
5
maverick
Can Splunk index events from my Checkpoint firewall logs? If so, how can I set that up?
by maverick Splunk Employee Splunk Employee in Getting Data In 04-27-2010
1 4
1
4
jradkowskiAAMC
Currently, all agents installed on hosts default to 'changeme' and this credential is still used when the forwarder i...
by jradkowskiAAMC Explorer in Getting Data In 04-26-2010
0 2
0
2
sivakumar_inbox
I had configured splunk forwarder and receiver in a Linux system as per the Admin manual. I tried searching the forwa...
by sivakumar_inbox Engager in Getting Data In 04-26-2010
1 2
1
2
cpenkert
We are on 4.05 and are using the default of memPoolMB = auto in indexes.conf. Is there a way I can find out what size...
by cpenkert Path Finder in Getting Data In 04-24-2010
1 5
1
5
SK110176
Referenced Doc: http://www.splunk.com/base/Documentation/4.1/Admin/Moreaboutforwarders I need to be able to send da...
by SK110176 Path Finder in Getting Data In 04-24-2010
1 4
1
4
Jaci
I've verified that the indexer (receiver) is the same or later version of Splunk as the forwarder. What log or config...
by Jaci Splunk Employee Splunk Employee in Getting Data In 04-23-2010
4 6
4
6
tpaulsen
We have on four Linux SLES10_64 Servers Splunk 3.4.4. Forwarders installed. Usually our production logs produce a con...
by tpaulsen Contributor in Getting Data In 04-23-2010
0 1
0
1
Alan_Bradley
I have one splunk forwarder I need to segregate from other indexes. I have created its own index and I need to know h...
by Alan_Bradley Path Finder in Getting Data In 04-23-2010
1 2
1
2
mctester
Currently, when I try to run a search in Splunk, I get the following error message: "Error in 'UnifiedSearch': You...
by mctester Communicator in Getting Data In 04-22-2010
1 1
1
1
tpaulsen
Hello, i want to collect logs from one forwarder (Splunk 4.0.10) and forward the data to different indexes on one in...
by tpaulsen Contributor in Getting Data In 04-22-2010
1 7
1
7
tier2ops
This has happened twice so far in a week. Users begin contacting me that they are unable to log in. Both times I ra...
by tier2ops Explorer in Getting Data In 04-21-2010
1 6
1
6
alextsui
Hello, when using the following setup in props.conf, i was able to get the sourcetypes I want. [source::/var/splunk/...
by alextsui Path Finder in Getting Data In 04-21-2010
2 1
2
1
jheilman
I have a set of logs that no longer appear to be being indexed. I had originally configured the monitor as follows......
by jheilman Explorer in Getting Data In 04-21-2010
0 2
0
2
rbruno7
Hi Guys, We have built a small Splunk app to retrieve and index web usage info from multiple SQL databases. My Splun...
by rbruno7 Explorer in Getting Data In 04-21-2010
0 6
0
6
JHill
I have a Splunk forwarder instance that appears to be returning a value of 2 during start up. I am curious as to wh...
by JHill Explorer in Getting Data In 04-20-2010
1 1
1
1
gshah
Server is running 4.1. This does not seem to be an issue for default udp (that is, udp/514) messages. [udp://9514]...
by gshah Engager in Getting Data In 04-20-2010
2 3
2
3
jheilman
I have a test Windows forwarder set up that is generating over 22,000 events relating to the splunk-optimize.exe proc...
by jheilman Explorer in Getting Data In 04-20-2010
2 1
2
1
the_wolverine
We need to get Splunk to display date formats using the Australian format of dd/mm/yyyy rather than the US format whi...
by the_wolverine Champion in Getting Data In 04-17-2010
1 2
1
2
jrodman
I have a test logfile I fed into Splunk: Apr 13 10:41:16 support05 kernel: [1815783.556088] usb 2-1: new full speed ...
by jrodman Splunk Employee Splunk Employee in Getting Data In 04-17-2010
0 3
0
3
tantingli
I let splunk monitor a directory of files. I found when any file got changed splunk will reindex all events in the fi...
by tantingli Explorer in Getting Data In 04-17-2010
2 8
2
8
cmccoy
How do you configure Splunk to monitor files within a VM? I installed Splunk within a VM and added a data input to m...
by cmccoy Engager in Getting Data In 04-17-2010
1 3
1
3
Chris_R_
Odd behaviour with some udp syslog input from a Panorama device (palo alto management device) and ArcSight connector ...
by Chris_R_ Splunk Employee Splunk Employee in Getting Data In 04-17-2010
0 5
0
5
Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...
Top Solution Authors