Thread Info | |||||
---|---|---|---|---|---|
$SPLUNK_DB for one of our Splunk Search Servers filled up recently. The root cause was apparently due to significant ...
by
teedilo
Path Finder
in
Getting Data In
05-26-2016
|
0
|
2
| |||
I want to use Volumes in indexes.conf to limit the space used by my indexes.
On each index, I see 4 paths : homePa...
by
yannK
Splunk Employee
in
Getting Data In
06-20-2017
|
4
|
1
| |||
When running the btool on the inputs.conf files on a Windows universal forwarder (v6.3.1), the results appear to be i...
by
wyfwa4
Communicator
in
Getting Data In
02-24-2016
|
4
|
6
| |||
My sample data
AAA, 0.5% BBB,0.10% CCC,0.20%
my search looks like this
base search | rex ".*?(?[^,]+),\s*?(?...
by
prathapkcsc
Explorer
in
Getting Data In
06-19-2017
|
1
|
9
| |||
Hello guys,
we have this config for outputs.conf :
*[tcpout] defaultGroup = ssl_splk_sitesAB_9997 useACK = true...
by
splunkreal
Motivator
in
Getting Data In
06-19-2017
|
0
|
9
| |||
Hi,
after we upgrade the universal forwarder on version 6.2 the security logs are not indexed anymore in the index...
by
arber
Communicator
in
Getting Data In
12-30-2014
|
0
|
11
| |||
Hi,
Having issues in not seeing our security logs from our DC. Here is our code:
[WinEventLog://Security]
disab...
by
andybento
New Member
in
Getting Data In
03-20-2015
|
0
|
6
| |||
Hi,
I Have a CSV file with some values that i am forwarding to my indexer and for this file, events and indexes ar...
by
patelya
New Member
in
Getting Data In
06-19-2017
|
0
|
4
| |||
On linux systems, only a process running as root can listen to ports < 1024. I want splunk to listen to syslog on UDP...
by
yannK
Splunk Employee
in
Getting Data In
10-30-2012
|
9
|
6
| |||
Hi guys
Im doing a correlation search where Im looking for hostnames and filtering for events I dont want. eg.
...
by
shiftey
Path Finder
in
Getting Data In
05-28-2015
|
1
|
9
| |||
Hi, we are having trouble installing Universal Forwarder (32-bit) to a server that has system specifications of: OS: ...
by
raventura
Observer
in
Getting Data In
12-19-2016
|
0
|
2
| |||
Hi, If i need to filtering some data in the log before forward to indexing, how to go abt doing it? thks
by
SplunkCSIT
Communicator
in
Getting Data In
02-13-2014
|
1
|
11
| |||
So, I'm slightly confused. I'm looking at the Splunk documentation and they reference only sending 50 GB/day to an in...
by
ltrand
Contributor
in
Getting Data In
12-13-2014
|
0
|
10
| |||
Hi to all, I configured a forwarder as following
In Splunk Server: - in /opt/splunk/etc/deployment-apps I copyed t...
by
andreac81
Explorer
in
Getting Data In
06-09-2017
|
0
|
5
| |||
Hello,
I am trying to index following files:
c:\test\access.log
c:\test\access_00.0.log
c:\test\access_00...
by
ofaura
Path Finder
in
Getting Data In
06-12-2017
|
0
|
3
| |||
All my other indexes are indexing data. I created a new one, and i need to have 1164 data and its only appear 994, i ...
by
madisonAvalos
Engager
in
Getting Data In
06-16-2017
|
0
|
1
| |||
Hi Splunkers!
I’d like to pick your brain to see if you know of 3-5 key windows event log events to monitor that w...
by
vanderaj2
Path Finder
in
Getting Data In
06-16-2017
|
2
|
1
| |||
I have a korn shell that creates a log. I want to run the script via the inputs.conf, every Monday at 5am. I don't wa...
by
riotto
Path Finder
in
Getting Data In
06-16-2017
|
0
|
6
| |||
Is it possible to have multiple tcp output groups in outputs.conf and have the events autoLB'd between them? My under...
by
sunnybrarjpmc
New Member
in
Getting Data In
06-16-2017
|
0
|
3
| |||
For example, if I put this in inputs.conf
[script:/bin/ls /*/lib /var/lib /usr/lib ]
sourcetype = ls
The latte...
by
yuanliu
SplunkTrust
in
Getting Data In
04-19-2017
|
0
|
7
| |||
Hi, I've reviewed almost all the question about event line breaking but still have some inconsistency with data inges...
by
msichani
Explorer
in
Getting Data In
06-16-2017
|
1
|
4
| |||
The substr function is not working for json logs for us in 6.5.2 for Dev version. Whereas the Prod version of the Spl...
by
pimco_rgoyal
Observer
in
Getting Data In
06-14-2017
|
0
|
10
| |||
I was wondering if possible for a single splunk universal forwarder to be managed by two different deployment servers...
by
vanderaj2
Path Finder
in
Getting Data In
06-16-2017
|
0
|
3
| |||
Hi,
I need to use Splunk rest command in search - but I wish to generate a POST request instead of GET. Is it poss...
by
lukasz92
Communicator
in
Getting Data In
03-08-2017
|
0
|
3
| |||
I am working in the FIX log messages and have two fields that contain timestamps. I need to check for one field and i...
by
isha_rastogi
Path Finder
in
Getting Data In
06-14-2017
|
0
|
8
|