| I am indexing a log file which doesn't have a timestamp, but have a few events that have completion time (how much ti... by isha_rastogi Path Finder in Getting Data In 12-18-2016 0 2 | 0 | 2 | ||
| SSL Question: What is the difference between TcpOutputProc and TcpOutputFd? I am getting an error message on my forw... by nmensah Explorer in Getting Data In 12-18-2016 0 1 | 0 | 1 | ||
| I have set the sourcetype for access logs in inputs.conf + props.conf before, but on one host it is not recognizing t... by alange Explorer in Getting Data In 12-16-2016 0 3 | 0 | 3 | ||
| Should it really be like this? I think it is a bug. In /var/log I have lots of files and dirs. I want to monitor the... by elof Path Finder in Getting Data In 12-16-2016 0 3 | 0 | 3 | ||
| Hopefully a simple question. I can see that in props.conf you can use source, [source::.../dads_logs/*.log], to cont... by rrussellstscied Explorer in Getting Data In 12-16-2016 0 3 | 0 | 3 | ||
| We have large number of log files to ingest and the machine shows - $ ulimit -n 64000 How high can we set the max_... by ddrillic Ultra Champion in Getting Data In 12-16-2016 0 1 | 0 | 1 | ||
| Hello Everyone, We are trying to monitor log files on a server using the Splunk universal forwarder. The logs direct... by VipulPathak Explorer in Getting Data In 12-15-2016 0 14 | 0 | 14 | ||
| I am trying to do a groupby operation at index time on Ironport logs. I have looked in all the documents and posts an... by ananthkumar12 Explorer in Getting Data In 12-15-2016 0 4 | 0 | 4 | ||
| I've configured inputs.conf like below, but I can't see any data. (Other stanzas for [perfmon:// are all working perf... by 1500372 Explorer in Getting Data In 12-15-2016 0 4 | 0 | 4 | ||
| Hello all. Apologies in advance if the answer to these questions are documented elsewhere, but I've not been able to... by cbaiocchetti New Member in Getting Data In 12-15-2016 0 1 | 0 | 1 | ||
| i want to reduce the number in my indexes by filtering out common Windows events such as 4688 event Id. I thought it ... by andy_macn New Member in Getting Data In 12-15-2016 0 1 | 0 | 1 | ||
| I have a couple of hosts that have the same version of Windows (2012 R2) that one will produce perfmon:memory data, a... by cpetterborg SplunkTrust 0 3 | 0 | 3 | ||
| Please excuse me for writing in Japanese. Splunk Freeで、分散サーチの機能を利用せずに、サーチヘッドとインデクサーを、 それぞれ別のサーバーへ配置することは可能でしょうか? また、... by amemiya New Member in Getting Data In 12-15-2016 0 2 | 0 | 2 | ||
| I am kind of new in Splunk and I am curious about something. When I install universal forwarder to a Windows server, ... by akif_kayapinar New Member in Getting Data In 12-14-2016 0 2 | 0 | 2 | ||
| The logs I've got only have log generation timestamps in them, and the timestamp in Splunk reflects the log generatio... by kalik Explorer in Getting Data In 12-14-2016 0 2 | 0 | 2 | ||
| We have a fairly large index in an indexer cluster of six indexers. What would be an easy way to remove this index fr... by ddrillic Ultra Champion in Getting Data In 12-14-2016 0 4 | 0 | 4 | ||
| We wonder whether [monitor:///<source>/logs/*.log] would monitor all log files in the <source>/logs directory and als... by ddrillic Ultra Champion in Getting Data In 12-14-2016 0 2 | 0 | 2 | ||
| Hello I have a number of devices logging to an index feeding Splunk via Syslog on 514/UDP. Now, I want to route logs... by j666gak Communicator in Getting Data In 12-14-2016 2 5 | 2 | 5 | ||
| I have following logs from a customer device: 0080101c40ba,10.10.1.2,1481421584,host1.labtest.com,error-message1,sev... by jgcsco Path Finder in Getting Data In 12-14-2016 1 8 | 1 | 8 | ||
| -health_checkin_date: 2016-10-30T09:45:28.824Z That is the line from a JSON event being sent into my Splunk instanc... by joshualarkins Explorer in Getting Data In 12-14-2016 1 3 | 1 | 3 | ||
| We are facing a few issues whereour endpoints (clients) may have the Splunk service stopped. Can we force a restart o... by koshyk Super Champion in Getting Data In 12-14-2016 0 3 | 0 | 3 | ||
| This works in the search bar |makemv delim="|", but not when I put that in the props.conf file. by Yepeza Path Finder in Getting Data In 12-14-2016 1 13 | 1 | 13 | ||
| Hi, we just set up our first Universal Forwarder which now works as expected. But it didn't do so initially, before ... by dwoehr Explorer in Getting Data In 12-14-2016 0 1 | 0 | 1 | ||
| Hello, I'm trying to figure out the following setup: At the moment we have one rotating log file that should be forw... by dwoehr Explorer in Getting Data In 12-14-2016 0 4 | 0 | 4 | ||
| Hi. We have recently been inadvertently sending some events to the null queue, due to a new data source that matche... by jhigginsmq Path Finder in Getting Data In 12-14-2016 0 5 | 0 | 5 |