| Hi, I'm struggling with an issue involving my old nemesis, inputs.conf rules :-). In this case, we have a catch-all... by mfrost8 Builder in Getting Data In 11-10-2016 1 2 | 1 | 2 | ||
| We will be installing the forwarder onto our domain controllers in DMZ. Question, can we hardwire a port on the DC w... by brdr Contributor in Getting Data In 11-10-2016 0 3 | 0 | 3 | ||
| Is there a way to use external lists with whitelist filtering? For example if I had systems A and B with several host... by Susannajuurinen Explorer in Getting Data In 11-10-2016 0 3 | 0 | 3 | ||
| Hi, I'm using Splunk Enterprise 6.5.0 with Universal forwarders 6.5.0 for some years now to index log files from .Ne... by sebch Engager in Getting Data In 11-10-2016 0 2 | 0 | 2 | ||
| Hello, I am trying to onboard an ActiveRoles server, however it doesn't seem that I'm configuring my inputs.conf ap... by sadkha Path Finder in Getting Data In 11-10-2016 0 3 | 0 | 3 | ||
| Hello All, Is this possible in Splunk where we can add new fields and there value will depends on condition? in tran... by snehalk Communicator in Getting Data In 11-10-2016 0 4 | 0 | 4 | ||
| Hi, I know Splunk will injest a TAR (and other types) file, my question is what if the file extension is NOT *.tar o... by dbcase Motivator in Getting Data In 11-10-2016 0 2 | 0 | 2 | ||
| Hello, I want to know a retirement policy of the fishbucket on the universal forwarder for a disk sizing. The data ... by Hajime Path Finder in Getting Data In 11-09-2016 0 5 | 0 | 5 | ||
| We need to monitor a log file on linux with the splunk forwarder(splunk user account which is local). Log file is own... by krishnacasso Path Finder in Getting Data In 11-09-2016 0 1 | 0 | 1 | ||
| Hi I have some universal forwaders installed on linux (suse) and solaris. I have a user "splunk" to log to those ma... by fernandoandre Communicator in Getting Data In 11-09-2016 0 2 | 0 | 2 | ||
| I'm trying to install Splunk Universal Forwarder on Red Hat OS. I am getting stuck at this step. Before this command,... by dmacndawk New Member in Getting Data In 11-09-2016 0 1 | 0 | 1 | ||
| Hi, What will splunk behave like in the two following cases: 1) File A.log, having the lines: 1 2 3 ... by reggie_123 Explorer in Getting Data In 11-09-2016 1 2 | 1 | 2 | ||
| i am test '_tcp_routing' in my virtual machines, before doing that on online system. simply i add: [monitor://afile] ... by crazyeva Contributor in Getting Data In 11-09-2016 0 1 | 0 | 1 | ||
| Hi, I've a universal forwarder on a Linux machine that forwards Security Onion logs to my Splunk instance. Logs are... by ozirus Path Finder in Getting Data In 11-09-2016 0 4 | 0 | 4 | ||
| You'll have to pardon the newbie question. I'm sure this is crazy easy, but I'm having the worst time figuring it out... by rh990 Engager in Getting Data In 11-08-2016 0 5 | 0 | 5 | ||
| One of the new features in Splunk 6.0+ is the capability of a forwarder assigning a timezone to an event in the situa... by muebel SplunkTrust 0 3 | 0 | 3 | ||
| Seeking help with TIME_FORMAT in props.conf. I'm trying to get Splunk to recognize a time format in the form of "J... by splk5000 New Member in Getting Data In 11-08-2016 0 6 | 0 | 6 | ||
| In inputs.conf for monitor stanza, can we write regex? If so, /opt/splunk/cgate* matches (/opt/splunk/cgateee) or ... by ankithreddy777 Contributor in Getting Data In 11-08-2016 0 2 | 0 | 2 | ||
| Hi, I am using below props file for CSV but data is not getting indexed or sent into Splunk. Need help in updating pr... by yanivdutt Explorer in Getting Data In 11-08-2016 0 3 | 0 | 3 | ||
| I have the following string in the events and I would like to mask the password text using sedcmd. Content={"Login":... by caitcait Explorer in Getting Data In 11-08-2016 0 2 | 0 | 2 | ||
| Hi, What is the procedure to monitor changes to file content? As per knowledge we can add some parameters to props.c... by nagarajugowdkal New Member in Getting Data In 11-07-2016 0 5 | 0 | 5 | ||
| I used the variable "$COMPUTERNAME" in my app's inputs.conf file. For all the PCs that got it, it's reporting their c... by tmontney Builder in Getting Data In 11-07-2016 0 3 | 0 | 3 | ||
| Please help me with props.conf file i have sample data below i want to extract time stamp from the below sample data.... by sravankaripe Communicator in Getting Data In 11-07-2016 0 6 | 0 | 6 | ||
| Hi, I'm looking at options for improving some reporting for a heavy feed from AD. Is INDEXED_EXTRACTIONS supported ... by a212830 Champion in Getting Data In 11-07-2016 0 4 | 0 | 4 | ||
| I'm looking for an option to remove the automatic timestamp from the csv output filename attached to emails. Accordi... by kearaspoor SplunkTrust 0 3 | 0 | 3 |