Getting Data In

Getting Data In
Community Activity
akcyril
I would like to experiment with entries in which time is mentioned as 1,2,3, .... , n; where the nth entry is the lat...
by akcyril New Member in Getting Data In 12-19-2016
0 1
0
1
rsingh
i am getting 2 different errors on my Splunk server - please see attached for errors, unsure what is wrong thanks fo...
by rsingh Explorer in Getting Data In 12-19-2016
0 5
0
5
princemanto2580
Hello, I have 2 Indexers along with 1 search head. Both the indexers are added under distributed search peer. From a...
by princemanto2580 Path Finder in Getting Data In 12-18-2016
0 2
0
2
isha_rastogi
I am indexing a log file which doesn't have a timestamp, but have a few events that have completion time (how much ti...
by isha_rastogi Path Finder in Getting Data In 12-18-2016
0 2
0
2
nmensah
SSL Question: What is the difference between TcpOutputProc and TcpOutputFd? I am getting an error message on my forw...
by nmensah Explorer in Getting Data In 12-18-2016
0 1
0
1
alange
I have set the sourcetype for access logs in inputs.conf + props.conf before, but on one host it is not recognizing t...
by alange Explorer in Getting Data In 12-16-2016
0 3
0
3
elof
Should it really be like this? I think it is a bug. In /var/log I have lots of files and dirs. I want to monitor the...
by elof Path Finder in Getting Data In 12-16-2016
0 3
0
3
rrussellstscied
Hopefully a simple question. I can see that in props.conf you can use source, [source::.../dads_logs/*.log], to cont...
by rrussellstscied Explorer in Getting Data In 12-16-2016
0 3
0
3
ddrillic
We have large number of log files to ingest and the machine shows - $ ulimit -n 64000 How high can we set the max_...
by ddrillic Ultra Champion in Getting Data In 12-16-2016
0 1
0
1
VipulPathak
Hello Everyone, We are trying to monitor log files on a server using the Splunk universal forwarder. The logs direct...
by VipulPathak Explorer in Getting Data In 12-15-2016
0 14
0
14
ananthkumar12
I am trying to do a groupby operation at index time on Ironport logs. I have looked in all the documents and posts an...
by ananthkumar12 Explorer in Getting Data In 12-15-2016
0 4
0
4
1500372
I've configured inputs.conf like below, but I can't see any data. (Other stanzas for [perfmon:// are all working perf...
by 1500372 Explorer in Getting Data In 12-15-2016
0 4
0
4
cbaiocchetti
Hello all. Apologies in advance if the answer to these questions are documented elsewhere, but I've not been able to...
by cbaiocchetti New Member in Getting Data In 12-15-2016
0 1
0
1
andy_macn
i want to reduce the number in my indexes by filtering out common Windows events such as 4688 event Id. I thought it ...
by andy_macn New Member in Getting Data In 12-15-2016
0 1
0
1
cpetterborg
I have a couple of hosts that have the same version of Windows (2012 R2) that one will produce perfmon:memory data, a...
by SplunkTrust SplunkTrust in Getting Data In 12-15-2016
0 3
0
3
amemiya
Please excuse me for writing in Japanese. Splunk Freeで、分散サーチの機能を利用せずに、サーチヘッドとインデクサーを、 それぞれ別のサーバーへ配置することは可能でしょうか? また、...
by amemiya New Member in Getting Data In 12-15-2016
0 2
0
2
akif_kayapinar
I am kind of new in Splunk and I am curious about something. When I install universal forwarder to a Windows server, ...
by akif_kayapinar New Member in Getting Data In 12-14-2016
0 2
0
2
kalik
The logs I've got only have log generation timestamps in them, and the timestamp in Splunk reflects the log generatio...
by kalik Explorer in Getting Data In 12-14-2016
0 2
0
2
ddrillic
We have a fairly large index in an indexer cluster of six indexers. What would be an easy way to remove this index fr...
by ddrillic Ultra Champion in Getting Data In 12-14-2016
0 4
0
4
ddrillic
We wonder whether [monitor:///<source>/logs/*.log] would monitor all log files in the <source>/logs directory and als...
by ddrillic Ultra Champion in Getting Data In 12-14-2016
0 2
0
2
j666gak
Hello I have a number of devices logging to an index feeding Splunk via Syslog on 514/UDP. Now, I want to route logs...
by j666gak Communicator in Getting Data In 12-14-2016
2 5
2
5
jgcsco
I have following logs from a customer device: 0080101c40ba,10.10.1.2,1481421584,host1.labtest.com,error-message1,sev...
by jgcsco Path Finder in Getting Data In 12-14-2016
1 8
1
8
joshualarkins
-health_checkin_date: 2016-10-30T09:45:28.824Z That is the line from a JSON event being sent into my Splunk instanc...
by joshualarkins Explorer in Getting Data In 12-14-2016
1 3
1
3
koshyk
We are facing a few issues whereour endpoints (clients) may have the Splunk service stopped. Can we force a restart o...
by koshyk Super Champion in Getting Data In 12-14-2016
0 3
0
3
Yepeza
This works in the search bar |makemv delim="|", but not when I put that in the props.conf file.
by Yepeza Path Finder in Getting Data In 12-14-2016
1 13
1
13
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors