| Thread Info | |||||
|---|---|---|---|---|---|
| 
        I am thinking about building an environment in a country where daylight saving time exists, but as for the server, I ...
        
         
           by 
           
                
                    
                        yutaka1005
                    
                
           
             
             
               Builder
             
           
           in
           Getting Data In
           
           
              
               09-29-2017
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hi, I'm brand new to Splunk and been given an existing Splunk environment to manage. I need to get a universal forwar...
        
         
           by 
           
                
                    
                        dougsummersett
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               09-28-2017
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hi all, 
  I tried to find a way to extract fields automatically after adding new data. 
  The input is of the type: ...
        
         
           by 
           
                
                    
                        DrFedtke
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               09-12-2015
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        All,  
  A bit concern for us lately is Splunk downtime. Search head clustering has been helpful, so now we're lookin...
        
         
           by 
           
                
                    
                        daniel333
                    
                
           
             
             
               Builder
             
           
           in
           Getting Data In
           
           
              
               11-29-2016
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        I am upgrading to Splunk 7.0. The installer hangs and does not complete. Running Win10 1703 on vmware 12 
  looking f...
        
         
           by 
           
                
                    
                        freedg
                    
                
           
             
             
               Engager
             
           
           in
           Getting Data In
           
           
              
               09-27-2017
             
           
         
        | 
		
		1
   | 
	  
	  5
	 | |||
| 
        Hi Experts I have following monitor stanza . I want to blacklist "data/xyz/logs/router.jar.log" but want to monitor "...
        
         
           by 
           
                
                    
                        vaibhavagg2006
                    
                
           
             
             
               Communicator
             
           
           in
           Getting Data In
           
           
              
               09-28-2017
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        Hi, I'm ingesting data in pure json and all fields are being extracted. However, all fields are strings regardless of...
        
         
           by 
           
                
                    
                        cdstealer
                    
                
           
             
             
               Contributor
             
           
           in
           Getting Data In
           
           
              
               09-26-2017
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        I have created an alert which checks if logs are not present in last 20 mins per source. I have around 32 source file...
        
         
           by 
           
                
                    
                        chintan_shah
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               09-21-2017
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        How to increase the retention time of Splunk monitoring console Reports in distributed environment?
        
         
           by 
           
                
                    
                        ahmedhassanean
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               09-27-2017
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        In our Slave-Apps directory on the 2 peers/indexers we have a custom app created by the prev admin which has setting ...
        
         
           by 
           
                
                    
                        hrithiktej
                    
                
           
             
             
               Communicator
             
           
           in
           Getting Data In
           
           
              
               09-22-2017
             
           
         
        | 
		
		1
   | 
	  
	  24
	 | |||
| 
        I've asked about this before and now I've re-loaded the raw data without any modifications. It looks like this (witho...
        
         
           by 
           
                
                    
                        RexStout
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               09-26-2017
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Hi All, We have the below query which is getting triggered everyday based on the missing UF server from the lookup ta...
        
         
           by 
           
                
                    
                        Hemnaath
                    
                
           
             
             
               Motivator
             
           
           in
           Getting Data In
           
           
              
               09-26-2017
             
           
         
        | 
		
		0
   | 
	  
	  13
	 | |||
| 
        Hello. 
  Again the question from me.=) 
  Noticed such a feature, if restart SplunkForwarder service, security event...
        
         
           by 
           
                
                    
                        templier
                    
                
           
             
             
               Communicator
             
           
           in
           Getting Data In
           
           
              
               01-28-2014
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hi, 
  We usually say that if we index more than 10GB per day per index, we should put maxDataSize = auto_high_volume...
        
         
           by 
           
                
                    
                        ctaf
                    
                
           
             
             
               Contributor
             
           
           in
           Getting Data In
           
           
              
               09-20-2017
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hi All, Currently I have request from the network team that they wanted to point the site 03r & 04r from index=net so...
        
         
           by 
           
                
                    
                        Hemnaath
                    
                
           
             
             
               Motivator
             
           
           in
           Getting Data In
           
           
              
               09-19-2017
             
           
         
        | 
		
		0
   | 
	  
	  10
	 | |||
| 
        Hi Folks, 
  we have below format logs and there is no time stamp on first 5 lines and we are getting error "failed t...
        
         
           by 
           
                
                    
                        lksridhar
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               09-26-2017
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I'm looking to find matching field (lets call this field action) from 2 different host with the same sourcetype. 
  e...
        
         
           by 
           
                
                    
                        mrtolu6
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               09-26-2017
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hi, i'm making a batch job status panel for websphere team . i need to show those jobs as pending state who are runni...
        
         
           by 
           
                
                    
                        Mohsin123
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               09-25-2017
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        hi, can you please tell me what is the right way to btool inputs.conf for a specific app context. I want to troublesh...
        
         
           by 
           
                
                    
                        Mohsin123
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               09-26-2017
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        I have a UF setup on a windows 2012 server. I am logging Win sec logs but I see some in the event viewer that are not...
        
         
           by 
           
                
                    
                        Jordan54
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               09-26-2017
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hi there, 
  Quick one, does Splunk freeze data based on bucket timestamp or event timestamp? 
  Cheers, 
  MHibbin
        
         
           by 
           
                
                    
                        MHibbin
                    
                
           
             
             
               Influencer
             
           
           in
           Getting Data In
           
           
              
               08-01-2013
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hi, 
  Seeking for an assistance on how can I automate splunk forwarder installation using windows script? Can I add ...
        
         
           by 
           
                
                    
                        dantimola
                    
                
           
             
             
               Communicator
             
           
           in
           Getting Data In
           
           
              
               09-26-2017
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        My clustered index sizes/event counts seem to occasionally mismatch a bit from indexer-to-indexer. This might result ...
        
         
           by 
           
                
                    
                        some_guy
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               03-05-2015
             
           
         
        | 
		
		1
   | 
	  
	  5
	 | |||
| 
        Hello all, 
  I collect all of my *nix logs into a central server that I has a UF installed on it. I have the splunk_...
        
         
           by 
           
                
                    
                        ZimmermanC1
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               09-18-2017
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I need to install 2 separate universal forwarders on the same Windows box. I have the install built, one via msi and ...
        
         
           by 
           
                
                    
                        pfabrizi
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               09-20-2017
             
           
         
        | 
		
		0
   | 
	  
	  2
	 |