| Thread Info | |||||
|---|---|---|---|---|---|
| 
        Minimum requirements for Splunk Universal Forwarder in 32-bit OS 
  If 2x six-core, 2+ GHz CPU, 12GB RAM, RAID 0 or 1...
        
         
           by 
           
                
                    
                        raventura
                    
                
           
             
             
               Observer
             
           
           in
           Getting Data In
           
           
              
               12-19-2016
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        is it possible to ssh Splunk (that is running on Windows machine) in order to run searches ?
        
         
           by 
           
                
                    
                        sbenamro
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               12-20-2016
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I understand that support for search head clustering was supposed to be added with version 6.3. Is that now supported...
        
         
           by 
           
                
                    
                        natebolt01
                    
                
           
             
             
               Engager
             
           
           in
           Getting Data In
           
           
              
               12-19-2016
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I want to send "wineventlog:security " logs to Heavy forwarder(KIWISERVER) and below are the configuration files that...
        
         
           by 
           
                
                    
                        chanamoluk
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               12-16-2016
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        We have a four (4) node indexer cluster. Under the 'Distributed Environment | Indexer Clustering', all four peers sho...
        
         
           by 
           
                
                    
                        agehring4823
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               12-19-2016
             
           
         
        | 
		
		1
   | 
	  
	  1
	 | |||
| 
        We have a existing infrastructure of Splunk where events are passed from multiple Linux boxes to Splunk indexers. 
  ...
        
         
           by 
           
                
                    
                        sarthakb
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               12-19-2016
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        I have a saved search that is being run through my dashboard with a text input using the "$token$" operator. I would ...
        
         
           by 
           
                
                    
                        _jgpm_
                    
                
           
             
             
               Communicator
             
           
           in
           Getting Data In
           
           
              
               12-15-2016
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I would like to experiment with entries in which time is mentioned as 1,2,3, .... , n; where the nth entry is the lat...
        
         
           by 
           
                
                    
                        akcyril
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               12-19-2016
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        i am getting 2 different errors on my Splunk server - please see attached for errors, unsure what is wrong 
  thanks ...
        
         
           by 
           
                
                    
                        rsingh
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               12-15-2016
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Hello, 
  I have 2 Indexers along with 1 search head. Both the indexers are added under distributed search peer. From...
        
         
           by 
           
                
                    
                        princemanto2580
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               12-18-2016
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I am indexing a log file which doesn't have a timestamp, but have a few events that have completion time (how much ti...
        
         
           by 
           
                
                    
                        isha_rastogi
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               12-14-2016
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        SSL Question: What is the difference between TcpOutputProc and TcpOutputFd? 
  I am getting an error message on my fo...
        
         
           by 
           
                
                    
                        nmensah
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               12-16-2016
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I have set the sourcetype for access logs in inputs.conf + props.conf before, but on one host it is not recognizing t...
        
         
           by 
           
                
                    
                        alange
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               12-16-2016
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Should it really be like this? I think it is a bug. 
  In /var/log I have lots of files and dirs. I want to monitor t...
        
         
           by 
           
                
                    
                        elof
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               03-07-2014
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hopefully a simple question. 
  I can see that in props.conf you can use source, [source::.../dads_logs/*.log], to co...
        
         
           by 
           
                
                    
                        rrussellstscied
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               12-16-2016
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        We have large number of log files to ingest and the machine shows - 
  $ ulimit -n
64000
 
  How high can we set the ...
        
         
           by 
           
                
                    
                        ddrillic
                    
                
           
             
             
               Ultra Champion
             
           
           in
           Getting Data In
           
           
              
               12-14-2016
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hello Everyone, 
  We are trying to monitor log files on a server using the Splunk universal forwarder. The logs dire...
        
         
           by 
           
                
                    
                        VipulPathak
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               10-22-2015
             
           
         
        | 
		
		0
   | 
	  
	  14
	 | |||
| 
        I am trying to do a groupby operation at index time on Ironport logs. I have looked in all the documents and posts an...
        
         
           by 
           
                
                    
                        ananthkumar12
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               12-11-2016
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        I've configured inputs.conf like below, but I can't see any data. (Other stanzas for [perfmon:// are all working perf...
        
         
           by 
           
                
                    
                        1500372
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               05-24-2016
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Hello all. Apologies in advance if the answer to these questions are documented elsewhere, but I've not been able to ...
        
         
           by 
           
                
                    
                        cbaiocchetti
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               12-15-2016
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        i want to reduce the number in my indexes by filtering out common Windows events such as 4688 event Id. I thought it ...
        
         
           by 
           
                
                    
                        andy_macn
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               12-15-2016
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I have a couple of hosts that have the same version of Windows (2012 R2) that one will produce perfmon:memory data, a...
        
         
           by 
           
                
                    
                        cpetterborg
                    
                
           
             
             
               SplunkTrust
             
           
           in
           Getting Data In
           
           
              
               12-13-2016
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Please excuse me for writing in Japanese. 
  Splunk Freeで、分散サーチの機能を利用せずに、サーチヘッドとインデクサーを、 それぞれ別のサーバーへ配置することは可能でしょうか? ま...
        
         
           by 
           
                
                    
                        amemiya
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               10-28-2016
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I am kind of new in Splunk and I am curious about something. When I install universal forwarder to a Windows server, ...
        
         
           by 
           
                
                    
                        akif_kayapinar
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               12-14-2016
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        The logs I've got only have log generation timestamps in them, and the timestamp in Splunk reflects the log generatio...
        
         
           by 
           
                
                    
                        kalik
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               12-14-2016
             
           
         
        | 
		
		0
   | 
	  
	  2
	 |