Getting Data In

Getting Data In
Community Activity
hcipartners
I have Splunk Enterprise on an AWS EC2 Server, and need to install forwarders on two other EC2 Instances. Can someon...
by hcipartners Engager in Getting Data In 02-29-2016
1 2
1
2
babcolee
We have a condition where we need to filter out data based on the byte count in the log. We have collapsed the source...
by babcolee Path Finder in Getting Data In 02-29-2016
0 4
0
4
Nesrinepfe
Hi, I would like to know the environment to install in case I use Splunk Enterprise (Trial version). I just want to ...
by Nesrinepfe Path Finder in Getting Data In 02-29-2016
0 2
0
2
lycollicott
First off, let me say that we do not have plans to purchase the VMware app. I would like to be able to identify any ...
by lycollicott Motivator in Getting Data In 02-29-2016
0 1
0
1
sbattista09
I see a lot of documentation for black listing by index name in outputs.conf, but I am a bit confused as to the varia...
by sbattista09 Contributor in Getting Data In 02-29-2016
0 5
0
5
bowesmana
I've read through a number of answers, but none quite gives what I want. I have daily tests that run and my dashboa...
by SplunkTrust SplunkTrust in Getting Data In 02-29-2016
0 4
0
4
splunkIT
We are using Hunk with MapR. There is a dispatch directory that Hunk uses for the reduce of the map reduce. /mapr/tmp...
by splunkIT Splunk Employee Splunk Employee in Getting Data In 02-26-2016
0 3
0
3
adamblock2
I am interested in forwarding syslog and Windows events from a DMZ to Indexers which reside inside our network. We a...
by adamblock2 Path Finder in Getting Data In 02-26-2016
0 4
0
4
kellihall
Each user can have two values of type: movement and check-in. There are some users that only have movement and never...
by kellihall New Member in Getting Data In 02-26-2016
0 1
0
1
ahmedhassanean
Dears, May I know please if it's possible to have a setup in which I will have only two machines: one of them will a...
by ahmedhassanean Explorer in Getting Data In 02-26-2016
0 1
0
1
michaelslab
All, The documentation is scattered in various places and not one place. Help. This should be simple and not ha...
by michaelslab New Member in Getting Data In 02-25-2016
0 6
0
6
w531t4
All -- I'm seeking any advice I can get at this point. A little background. I manage two different user communities ...
by w531t4 Path Finder in Getting Data In 02-25-2016
0 5
0
5
patrickcope
How to search a list of forwarders sending data to a single index or multiple indexes? ie: forwarder (A) sending to ...
by patrickcope New Member in Getting Data In 02-25-2016
0 1
0
1
kalianov
I need to monitor file changes and I want to know which changes were made. inputs.conf [fschange:///etc/passwd] d...
by kalianov Path Finder in Getting Data In 02-25-2016
0 1
0
1
athorat
Is there a way to restrict this search with upper case and lower case scenarios? index=aap_prod sourcetype="HDP:PROD...
by athorat Communicator in Getting Data In 02-25-2016
0 1
0
1
gozulin
The indexer pauses indexing when free space goes under 5GB on the main partition. This is caused by too many warm buc...
by gozulin Communicator in Getting Data In 02-25-2016
0 6
0
6
JKnightSplunk
Hi all, I'm looking to add some custom fields to the Splunk Forwarder, but am struggling to find the a way of achiev...
by JKnightSplunk Engager in Getting Data In 02-25-2016
0 3
0
3
sbattista09
I keep getting the "minimum free disk space (5000MB) reached for /var/run/splunk/dispatch" on one of my heavy forward...
by sbattista09 Contributor in Getting Data In 02-25-2016
0 2
0
2
Abilan1
Hi , We are about to reach the maximum size of the disk on our Indexer server. Please suggest if there is any way to...
by Abilan1 Path Finder in Getting Data In 02-25-2016
0 7
0
7
mahesh_ravji1
Hi. I have a requirement to route events to index based on the fields host, sourcetype, and index. Field host form...
by mahesh_ravji1 Explorer in Getting Data In 02-25-2016
1 5
1
5
hastrike
We are wanting to modify our Splunk forwarders on workstations to look at other log files and I am curious how to go ...
by hastrike New Member in Getting Data In 02-25-2016
0 10
0
10
arbabnazar
Hi, Can I enable the SSL for the universal forwarder that will access it through the public ip, but not the forwarde...
by arbabnazar New Member in Getting Data In 02-24-2016
0 1
0
1
mataharry
I have Linux servers with Splunk, and the process monit to check my processed. But sometimes I see an issue where mo...
by mataharry Communicator in Getting Data In 02-24-2016
2 2
2
2
apro
Hi, Currently I have a splunk server receiving logs from few servers. I will like to do a search that is scheduled ...
by apro Path Finder in Getting Data In 02-24-2016
0 7
0
7
JdeFalconr
If an input is specified identically in the inputs.conf file of multiple apps running on a Universal forwarder, will ...
by JdeFalconr Explorer in Getting Data In 02-24-2016
0 2
0
2
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...