| Hi Guys, I do data import from a CSV and I would like set the eventtime ( _time) to a specific column because the au... by nikkkc Path Finder in Getting Data In 07-27-2016 1 2 | 1 | 2 | ||
| Hi All, I got a request to create report for License Usage by Indexer Server and Top 10 Host usage per Indexer Serve... by kpavan Path Finder in Getting Data In 07-27-2016 0 4 | 0 | 4 | ||
| Why am I getting the following warning in splunkd.log WARN JobsFeed - Could not parse mtime for status.csv in searc... by jkloda Engager in Getting Data In 07-27-2016 3 1 | 3 | 1 | ||
| Hi How to get the user details from the Active directory with OU name using ldapsearch? by kiran331 Builder in Getting Data In 07-27-2016 0 1 | 0 | 1 | ||
| Hello, Is Splunk able to, before or after indexing, transpose column and rows in this way: original file: has colum... by test365498 Path Finder in Getting Data In 07-27-2016 0 10 | 0 | 10 | ||
| We found that we have a new server type with a new internal application that is using port 8089 and would not allow t... by psutton_et Explorer in Getting Data In 07-27-2016 0 5 | 0 | 5 | ||
| Splunk 4.1.4 on Win2008 R2, splunkweb is repeatedly terminating with "Bad file descriptor" error shown in web_serivce... by MattK Explorer in Getting Data In 07-27-2016 2 9 | 2 | 9 | ||
| We have a HF in UTC timezone that is received log events from an Universal Forwarder running on EDT timezone. The log... by bkumarm Contributor in Getting Data In 07-27-2016 0 6 | 0 | 6 | ||
| We made a mistake and logged a few 1000 fields in an event with a wrong format. Is there any way that we could edit t... by anoopsankar Engager in Getting Data In 07-27-2016 1 1 | 1 | 1 | ||
| Hey. My antivirus generates 4 html reports every day in a folder, but I see a different number of events every time ... by Shark2112 Communicator in Getting Data In 07-27-2016 0 1 | 0 | 1 | ||
| Hi all, I'm currently experiencing this challenge. At a customer site we have two identical syslog servers receivin... by pinVie Path Finder in Getting Data In 07-27-2016 0 2 | 0 | 2 | ||
| I have a forwarder which is configured to monitor 5 directories. Each directory has it's own sourcetype and one of th... by skoelpin SplunkTrust 0 2 | 0 | 2 | ||
| Dear All, I'm totally new to the business, I've never dealt with regex, logs or Splunk, etc. Some answers can be fou... by calebra05 New Member in Getting Data In 07-26-2016 0 1 | 0 | 1 | ||
| I have a table on my dashboard that displays particular information from logs but I am trying to add an event name to... by ssingh313 Path Finder in Getting Data In 07-26-2016 0 14 | 0 | 14 | ||
| I want to create an index in an indexer cluster and pull firewall logs to store in that index. by nishwanth Engager in Getting Data In 07-26-2016 0 2 | 0 | 2 | ||
| I have a server which transfers logs to the Splunk server, but I don't know where it is stored in Splunk. Can someone... by nishwanth Engager in Getting Data In 07-26-2016 0 2 | 0 | 2 | ||
| I did the two following searches using the same license_usage.log file and got different results for yesterday's tota... by coleman07 Path Finder in Getting Data In 07-26-2016 0 3 | 0 | 3 | ||
| We have a UF on RHEL that forwards some files fine but one that is not being forwarded. I recently added a file to fo... by daddyoh Explorer in Getting Data In 07-26-2016 0 3 | 0 | 3 | ||
| All, I want to set aside a handful of indexers to store important data. I have a heavy forwarder setup. So should b... by daniel333 Builder in Getting Data In 07-26-2016 0 3 | 0 | 3 | ||
| I have a logs stored in splunk and they are of sourcetype=test, but I recently found this app that parses these type ... by mkudejim Explorer in Getting Data In 07-26-2016 1 8 | 1 | 8 | ||
| Despite having recently finished the Splunk Admin course, I'm still fuzzy on the terms "index-time" and "search-time"... by DaClyde Contributor in Getting Data In 07-26-2016 2 7 | 2 | 7 | ||
| I need to return a "yes" if (host=A has events > 0 and host=B has events > 0) else '"no" by riotto Path Finder in Getting Data In 07-26-2016 0 5 | 0 | 5 | ||
| After upgrading Splunk Universal Forwarder to version 6.4.0 or above, Splunk will no longer start and the following e... by dshakespeare_sp Splunk Employee 3 2 | 3 | 2 | ||
| Is it possible to set up Splunk with Just 1 Indexer, and 1 Search head? I began to attempt this through the Distribut... by Jarohnimo Builder in Getting Data In 07-25-2016 0 8 | 0 | 8 | ||
| I am trying to set up a universal forwarder (Windows) to send data to our new Splunk Light trial account. I am follo... by lorenh Explorer in Getting Data In 07-25-2016 0 6 | 0 | 6 |