| My 6.3.1 inputs.conf is: [monitor://E:\Tomcat-instance1\logs] index=instance1_appl sourcetype=tomcat-appl ignoreolde... by lycollicott Motivator in Getting Data In 11-24-2015 0 1 | 0 | 1 | ||
| Hi. I just installed Splunk Enterprise 6.3 on a VM running Windows Server 2012. The install went fine, but when I... by _dave_b Communicator in Getting Data In 11-24-2015 0 3 | 0 | 3 | ||
| I have an ldapsearch that is successfully retrieving multiple AD attributes including the whenCreated attribute. Unf... by kearaspoor SplunkTrust 0 4 | 0 | 4 | ||
| Hi, I have complex events in files forwarded from Windows hosts with Universal Forwarders. These files are zip-compr... by lukasz92 Communicator in Getting Data In 11-24-2015 0 5 | 0 | 5 | ||
| Well, this is technically a Unix question but still asked it here since it involves with Splunk. I already installed... by lloydknight Builder in Getting Data In 11-24-2015 0 2 | 0 | 2 | ||
| I have a particular log file that for some reason, the forwarder will not read and send the data to the indexer. I se... by proylea Contributor in Getting Data In 11-23-2015 0 5 | 0 | 5 | ||
| Dears, i have configured scripted input that poll snmp of network devices using snmpwalk command but problem that w... by ahmedhassanean Explorer in Getting Data In 11-23-2015 0 1 | 0 | 1 | ||
| We are running SPLUNK 6.1.4. We have a server with a REST API feed which every so often stops processing. To start it... by jasonhebron New Member in Getting Data In 11-22-2015 0 1 | 0 | 1 | ||
| I have a group of hosts that use the blacklist function in a monitor stanza in inputs.conf. Here is the referenced st... by mdinkins Engager in Getting Data In 11-21-2015 0 1 | 0 | 1 | ||
| I need to add an additional line break to events at the heavy forwarder. I'm trying to use transforms.conf: [add_lin... by mkemmerer Explorer in Getting Data In 11-20-2015 0 1 | 0 | 1 | ||
| Hi, I would like to remove data from an index when the file read is renamed. I have a file (prog.log.run) which con... by SirHill17 Communicator in Getting Data In 11-20-2015 0 1 | 0 | 1 | ||
| I am forwarding data from heavy-forwarder (HF-1) to heavy-forwarder(HF-2) which are in different network IP range. E... by splunker12er Motivator in Getting Data In 11-20-2015 0 1 | 0 | 1 | ||
| I acquired some logs from a scrip (close to ps.sh) with a timestamp correctly recognized at index time. The problem i... by gcusello SplunkTrust 0 2 | 0 | 2 | ||
| I configured the following: 1) Malwarebytes syslog configured to send syslog to Splunk server 2) Configured rsyslog.... by jwalzerpitt Influencer in Getting Data In 11-20-2015 0 2 | 0 | 2 | ||
| Will it break anything? Will it violate any certificates? I guess index=_internal will probably show a new machine fo... by hylam Contributor in Getting Data In 11-20-2015 0 1 | 0 | 1 | ||
| HI, I think this is a rather silly question, but I haven't been working with Splunk for too long and just can't figu... by omuelle1 Communicator in Getting Data In 11-19-2015 1 4 | 1 | 4 | ||
| Hi. Just installed Splunk for the first time today. As a tes,t I took a CSV file and indexed it, and it worked fi... by estepgi New Member in Getting Data In 11-19-2015 0 2 | 0 | 2 | ||
| I recently upgraded Splunk to 6.3. Our environment has 1 search head, 2 indexers and 1 deployment/licensing server a... by stevepraz Path Finder in Getting Data In 11-19-2015 2 1 | 2 | 1 | ||
| For Windows event-log events, Splunk displays the first 5 lines followed by "Show all [n] lines". Most of the time, t... by chris_brown_ral New Member in Getting Data In 11-19-2015 0 2 | 0 | 2 | ||
| I signed up for a Splunk Cloud trial, and set up a universal forwarder on one of our EC2 instances. However, I keep g... by pjoiner Explorer in Getting Data In 11-18-2015 0 5 | 0 | 5 | ||
| So I am trying to configure Hunk 6.3.1 to search my avro files in Hadoop. Here is an example of these .avro files in... by splunkIT Splunk Employee 0 2 | 0 | 2 | ||
| Hello Experts, I am very new to Splunk. I can import data into Splunk from .csv file by: add data->select source->so... by chaseto Explorer in Getting Data In 11-18-2015 1 5 | 1 | 5 | ||
| Hi, folks -- I'm using Splunk 6.0.1. I'm trying to ingest JSON and have the JSON syntax highlighting automatically p... by minerjaime Engager in Getting Data In 11-18-2015 0 2 | 0 | 2 | ||
| Hi guys, I am trying to run a sedcmd in props.conf and this is regex that I need to replace my internal IPs. SEDCMD... by csingh23 New Member in Getting Data In 11-18-2015 0 5 | 0 | 5 | ||
| I have 2 universal forwarders pointing to 1 receiver. All are Windows 64. I confirm that they are both "seen" by usi... by mr_dombat Explorer in Getting Data In 11-18-2015 0 2 | 0 | 2 |