| Thread Info | |||||
|---|---|---|---|---|---|
| 
      
        If I have a field value that is URL encoded then base-64 encoded, is it possible to have Splunk decode this field bef...
        
       
         
           by 
           
                
                    
                        hulahoop
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Getting Data In
           
           
              
               03-08-2010
             
           
         
        
      | 
   
		
		3
   
 | 	 
	  
	  7
	 
 | |||
| 
      
        Apart from the fact that a lightforwarder does not have a web UI, what are the main differences between the 2 apps?
        
       
         
           by 
           
                
                    
                        Mick
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Getting Data In
           
           
              
               03-09-2010
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        Hi  
  I have set up a light weight forwarder that appears to be getting data to the indexer. But I can't search for ...
        
       
         
           by 
           
                
                    
                        chris
                    
                
           
             
             
               Motivator
             
           
           in
           Getting Data In
           
           
              
               03-03-2010
             
           
         
        
      | 
   
		
		2
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        I need to do the following on my forwarder: 
  Forward all data received and gathered by the forwarder to Splunk inde...
        
       
         
           by 
           
                
                    
                        Alan_Bradley
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               02-22-2010
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        [I heard this question on an internal mailing list, but it seemed generally relevant so asking it here too] 
  I have...
        
       
         
           by 
           
                
                    
                        Justin_Grant
                    
                
           
             
             
               Contributor
             
           
           in
           Getting Data In
           
           
              
               02-22-2010
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        The use of LINE_BREAKER is a bit cryptic to me... ok, a lot. But I think I've managed to figure out how to break my X...
        
       
         
           by 
           
                
                    
                        hulahoop
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Getting Data In
           
           
              
               02-05-2010
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  6
	 
 | |||
| 
      
        What I'm trying to do: at index time, create a multiline event based on a unique ID. In the data sample below, I need...
        
       
         
           by 
           
                
                    
                        hulahoop
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Getting Data In
           
           
              
               02-05-2010
             
           
         
        
      | 
   
		
		2
   
 | 	 
	  
	  6
	 
 | |||
| 
      
        Sometimes Splunk sets the sourcetype on an incoming file as breakable_text or too_small. What determines these source...
        
       
         
           by 
           
                
                    
                        Yancy
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               01-28-2010
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        I'm trying to use Splunk to monitor both runtime metrics and configuration state of a server application like JBoss o...
        
       
         
           by 
           
                
                    
                        Justin_Grant
                    
                
           
             
             
               Contributor
             
           
           in
           Getting Data In
           
           
              
               01-25-2010
             
           
         
        
      | 
   
		
		2
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        Are there ways in Splunk to monitor and index any activity on Windows Registry?
        
       
         
           by 
           
                
                    
                        Ledio_Ago
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Getting Data In
           
           
              
               01-20-2010
             
           
         
        
      | 
   
		
		2
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        I have a directory /logdir and it contains various types of files, such as apache logs, syslog files, local applicati...
        
       
         
           by 
           
                
                    
                        jrodman
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Getting Data In
           
           
              
               01-15-2010
             
           
         
        
      | 
   
		
		2
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        What do I need to do to set the correct hostname for an event?
        
       
         
           by 
           
                
                    
                        matt
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Getting Data In
           
           
              
               01-15-2010
             
           
         
        
      | 
   
		
		2
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        When my selected coldToFrozenScript runs, which can take 10 minutes, the splunk search interface stops working until ...
        
       
         
           by 
           
                
                    
                        jrodman
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Getting Data In
           
           
              
               01-15-2010
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        I have data indexed but the "all indexed data" dashboard module is empty. Searching for * over all time produces no r...
        
       
         
           by 
           
                
                    
                        cfrln
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               01-14-2010
             
           
         
        
      | 
   
		
		2
   
 | 	 
	  
	  2
	 
 |