| Hi, I am trying a POC on my personal PC where Forwarder is on one machine (Linux)Indexer + Search Head on another m... by deepak02 Path Finder in Getting Data In 02-02-2017 0 2 | 0 | 2 | ||
| Bad regex value: '\s+([.-\w]+)\s+RT_FLOW', of param: transforms.conf / [dvc_for_junos_fw] / REGEX; why: invalid range... by Waltersr24 New Member in Getting Data In 02-02-2017 0 2 | 0 | 2 | ||
| I need to get a proper timestamp from raw data that looks like this: Date Of Incident: 12/02/2015 12:00:00 AM, Time ... by tgendron_splunk Splunk Employee 1 7 | 1 | 7 | ||
| In order to filter out non-administrator logon events on WinEventLog:Security sourcetype, I inserted the following st... by fab73 Path Finder in Getting Data In 02-02-2017 0 5 | 0 | 5 | ||
| Hello Team, I have some confusion on calculating maxTotalDataSizeMB for configuring in indexes.conf file. Below are ... by hemendralodhi Contributor in Getting Data In 02-01-2017 0 6 | 0 | 6 | ||
| hi.. in one of my windows server the universal forwarder stopped unexpected. found and restarted the universal forwa... by 82padarthi Explorer in Getting Data In 02-01-2017 0 10 | 0 | 10 | ||
| I have log file that has combination of plain text and key value pairs separated by "|". How can i extract all the fi... by jayakumar89 Explorer in Getting Data In 02-01-2017 0 4 | 0 | 4 | ||
| So... I am attempting to setup a TCP input, which will automatically set metadata, from the event. The _Raw looks li... by ericmck2000 Explorer in Getting Data In 02-01-2017 0 2 | 0 | 2 | ||
| Hi Splunkers, Is there any way to list all the saved searches in Splunk? I want to export the saved searches details... by praveenbandi Explorer in Getting Data In 02-01-2017 1 2 | 1 | 2 | ||
| I have configured monitoring for a set of files. I have configured the props.conf to use the 'last modified' time of ... by aholzer Motivator in Getting Data In 02-01-2017 0 7 | 0 | 7 | ||
| I have rows where data looks like.. Value1^Value2^Value3Value4^Value5Value6Value7^Value8 My query (below)... searc... by ereed18 Engager in Getting Data In 02-01-2017 0 2 | 0 | 2 | ||
| The Error Message on the screen isenter code here: "UniversalForwarder Setup ended prematurely" Versions older tha... by christopherr_sp Splunk Employee 4 1 | 4 | 1 | ||
| Or to restate the question : Why is Splunk Web reflecting the results of the CLI command, but inputs.conf file doesn'... by msutfin1 Explorer in Getting Data In 01-31-2017 1 5 | 1 | 5 | ||
| I have a csv file kept in a central path which is only uploaded once in a day. The moment i search the data on my sea... by simon21 Path Finder in Getting Data In 01-31-2017 0 1 | 0 | 1 | ||
| this is the format: {<!-- --> "epoch": "1485892851.94944", "id": "3952418", "name": "WMI Performance... by dperry Communicator in Getting Data In 01-31-2017 0 3 | 0 | 3 | ||
| I have pushed configurations to at least 15 servers. 12 servers out of these 15 are returning with these errors, wher... by vr2312 Builder in Getting Data In 01-31-2017 0 5 | 0 | 5 | ||
| I am trying to make Splunk read/index a CSV that is of 1.5KB. I have used the traditional CRCSALT=>SOURCE> tag in t... by vr2312 Builder in Getting Data In 01-31-2017 1 11 | 1 | 11 | ||
| On the Windows client server (splunkforwarder-6.2.1-245427-x64-release.msi) the inputs.conf file contains: [WinEvent... by andrewcg Path Finder in Getting Data In 01-31-2017 0 8 | 0 | 8 | ||
| 12/02/2015 12:00:00 AM, Execute time: 0150 looking to extract the date and the 24hr time pls by Esky73 Builder in Getting Data In 01-31-2017 0 6 | 0 | 6 | ||
| My log source generates events ended with null-character ('\x00') and sends them to Splunk via TCP in chunks every 10... by vsilchev Explorer in Getting Data In 01-31-2017 0 7 | 0 | 7 | ||
| Have data that Splunk is struggling with and needs props.conf and transforms.conf. The year/month/date followed by t... by smudge797 Path Finder in Getting Data In 01-30-2017 0 3 | 0 | 3 | ||
| Hi, The architect of the deployment is UF(Windows)->HF->Indexer->SH, only UF is installed in Windows platform and all... by jimmyzhangau New Member in Getting Data In 01-30-2017 0 2 | 0 | 2 | ||
| Simple scenario app_a/default/props.conf 25_app_a/default/props.conf The 25_app_a is an exact copy aside from the c... by leonphelps_s Path Finder in Getting Data In 01-30-2017 4 11 | 4 | 11 | ||
| I am new to Splunk, so please forgive me if the answer to the question is obvious.... I am trying to index W3C IISlo... by meskildsen New Member in Getting Data In 01-30-2017 0 11 | 0 | 11 | ||
| Hi I currently have tried a lot of things but can't seem to get the data into Splunk. I have a server sending syslog... by danfein New Member in Getting Data In 01-30-2017 0 3 | 0 | 3 |