Thread Info | |||||
---|---|---|---|---|---|
I've seen a few postings on this topic, but there doesn't seem to be final solution. I'm getting up to four different...
by
cmeo
Contributor
in
Getting Data In
08-11-2011
|
2
|
4
| |||
I have a subset of servers that all of their logs parse the timestamps incorrectly at 12 (noon)..
sample log lines...
by
mcafeesecure
Explorer
in
Getting Data In
05-15-2012
|
0
|
1
| |||
I have a app that is deployed on a host that polls a csv file. I can get data in to the Splunk indexer, but it does n...
by
virtualpony
Path Finder
in
Getting Data In
05-14-2012
|
0
|
5
| |||
In my transforms.conf I have this filter that does not work
[dropevents]
REGEX = (?msi)^host=server1.*^EventCod...
by
hartfoml
Motivator
in
Getting Data In
05-15-2012
|
0
|
1
| |||
If I've this in the outputs.conf in the fowarder:
[tcpout]
autoLB = true
autoLBFrequency = 10
compressed ...
by
fuster_j
Path Finder
in
Getting Data In
05-15-2012
|
0
|
2
| |||
I have several text format log files in which I need help in linebreaking them into the appropriate events that I nee...
by
JeffTanYH
Engager
in
Getting Data In
05-13-2012
|
0
|
3
| |||
With Windows 2008 (and Vista) event logs are now much more detailed, however there are some problems with multiple fi...
by
bojanz
Communicator
in
Getting Data In
08-30-2010
|
2
|
3
| |||
I added a sourcetype, weblogic_access_log, with its customized field (wl_kv_and_fields ) in props.conf and transforms...
by
shangshin
Contributor
in
Getting Data In
05-15-2012
|
0
|
2
| |||
After upgrading a Solaris SPARC forwarder from Splunk 3.4.9 to 4.1.4 (build 82143) one log file stopped being indexed...
by
kaufmanm
Communicator
in
Getting Data In
05-14-2012
|
0
|
3
| |||
This question may seem pretty silly but I'm really clueless about SPLUNK.
I do know where to configure the props.c...
by
JeffTanYH
Engager
in
Getting Data In
05-15-2012
|
0
|
2
| |||
Is there an easy way to download/retrieve the original source file via the web interface after finishing a search? It...
by
myli12
Path Finder
in
Getting Data In
03-13-2012
|
0
|
6
| |||
I am seeing a continuous stream of error messages on one of my indexers, such as this sample:
03-13-2012 15:28:33....
by
eugenekogan
Explorer
in
Getting Data In
03-13-2012
|
0
|
1
| |||
Hello,
I have installed splunk on a FreeBSD 8.3 server and a universal forwarder on a different FreeBSD machine th...
by
gkontos
New Member
in
Getting Data In
05-14-2012
|
0
|
1
| |||
What is the best way to change the hostname's of the forwarders (Linux)? We have change our naming convention. I chan...
by
khhenderson
Path Finder
in
Getting Data In
05-14-2012
|
1
|
3
| |||
This is a weird situation. I have on a number of Windows hosts running the heavyweight forwarder the following in loc...
by
dsg18096
New Member
in
Getting Data In
05-08-2012
|
0
|
3
| |||
I have a working snmp log file which I can search and email the data "anomosied" successfuly now however it i emailin...
by
asand100
New Member
in
Getting Data In
05-12-2012
|
0
|
2
| |||
I am trying to create a report of network bytes from the Universal Forwarder, WMI is not an option for me. Here is an...
by
mlevenson
Explorer
in
Getting Data In
05-11-2012
|
0
|
1
| |||
Once I have indexed a group of files into Splunk, is there a method/command where I can delete only one of those file...
by
efelder0
Communicator
in
Getting Data In
05-11-2012
|
0
|
1
| |||
I have a log structure like so:
/opt/data/logs/tomcat/foo or /opt/data/logs/tomcat/bar
the logs themselves are ...
by
mmattek
Path Finder
in
Getting Data In
05-08-2012
|
0
|
3
| |||
Wondering if it is possible to have our indexer in our datacenter but another splunk server to show graphs and do the...
by
mikezupan
Engager
in
Getting Data In
05-10-2012
|
0
|
2
|