| We are processing CSV files to index in Splunk, but the Splunk forwarder is always forwarding files twice. Can you pl... by dhavamanis Builder in Getting Data In 04-12-2016 0 2 | 0 | 2 | ||
| I am using Splunk Enterprise (Amazon Market Place AMI) I have added Forwarding receiving port 9997 Installed universa... by sureshsala Explorer in Getting Data In 04-12-2016 0 1 | 0 | 1 | ||
| Trying to determine why some of my forwarders sending in data from Windows virtual desktop instances are having their... by stevepraz Path Finder in Getting Data In 04-12-2016 0 3 | 0 | 3 | ||
| Hi Guys, Am i not sure if anyone has a solution for this. But I am not able to get any output when i run the linux fi... by samaikins New Member in Getting Data In 04-12-2016 0 2 | 0 | 2 | ||
| Hello Guys, I have installed a Splunk Universal Forwarder in my environment and set the deployment server. I also ha... by splunk_kk Path Finder in Getting Data In 04-11-2016 0 2 | 0 | 2 | ||
| Hello, I have several questions about splunk's backend to which I was unable to find a clear answer : 1) What is Sp... by 4Name Explorer in Getting Data In 04-11-2016 1 3 | 1 | 3 | ||
| Hello! I was wondering how to use a directory name (segment) as an event tag. For example: C:\bin\code\python\test_... by lsparrow New Member in Getting Data In 04-11-2016 0 1 | 0 | 1 | ||
| Im getting below error on my heavy forwarder logs, 6 indexers are connect that HF , 4 indexers are working fine. Only... by brod_geico Path Finder in Getting Data In 04-11-2016 0 3 | 0 | 3 | ||
| Hey there, We have a distributed Splunk environment... so, we have universal forwarders sending data to a heavy for... by michael_sleep Communicator in Getting Data In 04-11-2016 0 1 | 0 | 1 | ||
| In my new data set, the time comes in the format 1652 as it relates to 4:52pm. However, when it is before 1AM it come... by svercelli Path Finder in Getting Data In 04-11-2016 0 1 | 0 | 1 | ||
| Is there a process I can use with Splunk to pull audit logs on how, who, when, and where directories are being create... by pnv2254 New Member in Getting Data In 04-11-2016 0 2 | 0 | 2 | ||
| Hi, I have installed Splunk light in Windows and in Linux server also. I have installed a universal forwarder in the... by Monica7 New Member in Getting Data In 04-11-2016 0 1 | 0 | 1 | ||
| I have Splunk Light on Windows and the Universal Forwarder on Raspberry. According to docs, I need to create a server... by andig2 Engager in Getting Data In 04-11-2016 0 2 | 0 | 2 | ||
| Hi All, I need to collect the logs from a Windows machine into Splunk without installing any agent (universal forwar... by kpavan Path Finder in Getting Data In 04-11-2016 0 5 | 0 | 5 | ||
| “I am working with a customer who is a licensed and valid support contract holder with Splunk. They are currently run... by trflesher Explorer in Getting Data In 04-11-2016 0 13 | 0 | 13 | ||
| Is it even possible to configure Windows Event Logs through command line? PS C:\Program Files\SplunkUniversalForwar... by dlogvinenko Engager in Getting Data In 04-11-2016 0 1 | 0 | 1 | ||
| Hi I would like to find out how I can "strip out" events from a input file before they reach the splunk indexer. I... by itsomana Path Finder in Getting Data In 04-09-2016 3 6 | 3 | 6 | ||
| Hello, I am using FIELD_DELIMITER=; and am working on data that use commas instead of decimals. I want to use a SED ... by Maite35 Explorer in Getting Data In 04-09-2016 1 11 | 1 | 11 | ||
| I have had a host go down in aws that was not recoverable a few weeks ago and the universal forwarder is still showin... by Brolly75 New Member in Getting Data In 04-09-2016 0 1 | 0 | 1 | ||
| I have a monitor that that isn't working. I turned debug on in log.cfg, and the Universal Forwarder reports no match ... by lisaac Path Finder in Getting Data In 04-08-2016 0 1 | 0 | 1 | ||
| Hey, I am a total Splunk Noob. I am trying out Splunk Light. I can successfully import a file, but I cannot get sp... by belljar1 New Member in Getting Data In 04-08-2016 0 4 | 0 | 4 | ||
| I have an index "main" and several sources associated with this index. The size limit of the index has been reach (15... by henrym22 New Member in Getting Data In 04-08-2016 0 4 | 0 | 4 | ||
| Hi, If I have multiple matching TZ references in my props.conf on my indexer which one does it use? Is it just the o... by JeremyHagan Communicator in Getting Data In 04-07-2016 0 2 | 0 | 2 | ||
| Hi, Splunk FSchange is deprecated. Is there another way to replicate information of what fschange does? I wan to sh... by steadph New Member in Getting Data In 04-07-2016 0 2 | 0 | 2 | ||
| Hi, I've mounted some NFS and nfs locally to Splunk some files I want to monitor remotely. Problem is files are con... by abonuccelli_spl Splunk Employee 0 2 | 0 | 2 |