Getting Data In

Getting Data In
Community Activity
amal4885
I'm on Splunk 6.2 at the moment. I've specified a folder to monitor to collect NPS logs from a Windows 2012 server. T...
by amal4885 Explorer in Getting Data In 08-26-2015
0 6
0
6
jamesvz84
I am trying to take a TCP feed that is setting sourcetype=sources, and want to split the events into separate indexes...
by jamesvz84 Communicator in Getting Data In 08-26-2015
0 2
0
2
jodros
Following on from; http://splunk-base.splunk.com/answers/7001/udp-drops-on-linux Are any of you showing drops for sy...
by jodros Builder in Getting Data In 08-26-2015
3 6
3
6
jamesvz84
The following docs should how to override sourcetype: http://docs.splunk.com/Documentation/Splunk/6.2.5/Data/Advanced...
by jamesvz84 Communicator in Getting Data In 08-26-2015
0 1
0
1
jcrua0
When I run a search for "All Time" it looks to stop displaying data beyond 90 days into the past. Where's the config ...
by jcrua0 New Member in Getting Data In 08-26-2015
0 1
0
1
tony_alibelli
I have two types of people that need to access the same data source, but one of them must access anonymized data. I ...
by tony_alibelli New Member in Getting Data In 08-26-2015
0 1
0
1
Federica_92
Hi everyone, I set up a forwarder that started to index data logs from this morning, but it didn't send all the prio...
by Federica_92 Communicator in Getting Data In 08-26-2015
0 3
0
3
envato_dennis
We had a disk failure on our indexer. During this time, Splunk was thinking it was indexing data. We had to stop splu...
by envato_dennis New Member in Getting Data In 08-26-2015
0 2
0
2
rupesh_patil20
I want to assign the count of users on the X-axis where series of Zipcode on Y-axis. I have one .csv file which has t...
by rupesh_patil20 Path Finder in Getting Data In 08-25-2015
0 6
0
6
kkossery
Hi Experts, I'm trying to setup the Windows Forwarder on different servers to forward the status of Windows Updates ...
by kkossery Communicator in Getting Data In 08-25-2015
0 3
0
3
charlou
I'm trying, in vain, to get answers from the REST API as described here: http://dev.splunk.com/view/basic-tutorial/SP...
by charlou Engager in Getting Data In 08-25-2015
0 2
0
2
jravida
Hi folks, I just got a new data feed where my events come in as a multiline event, with one key/value pair on each l...
by jravida Communicator in Getting Data In 08-25-2015
0 2
0
2
odedtagar
I'm trying to index a json file (below) using the preview of the Add data>Set sourcetype window, but every configurat...
by odedtagar New Member in Getting Data In 08-25-2015
0 1
0
1
chrisboy68
Hi, I have been banging my head for a while. I have a couple of flat files that are a monitored input directly on t...
by chrisboy68 Contributor in Getting Data In 08-25-2015
0 2
0
2
oliverj
I am trying to monitor several individual files for changes. For example, I will watch "FILE1.log" If that file is ap...
by oliverj Communicator in Getting Data In 08-25-2015
2 3
2
3
laiyongmao
hi I use the heavyforwarder forward to indexer,but ... 01-17-2014 10:49:26.162 +0800 WARN TcpOutputFd - Connect to ...
by laiyongmao Path Finder in Getting Data In 08-25-2015
0 2
0
2
Abilan1
Hi, I have added my log folder in Splunk monitoring. I want to exclude the files that start with Test from Splunk mo...
by Abilan1 Path Finder in Getting Data In 08-24-2015
0 8
0
8
staftly
Is there a way to accurately determine the volume of events being dropped to the nullQueue? I have a standard props ...
by staftly New Member in Getting Data In 08-24-2015
0 1
0
1
pranav_agile
Hi, I am trying to get logs from two different servers running Tomcat application, but have the same location. The f...
by pranav_agile Explorer in Getting Data In 08-24-2015
0 8
0
8
tristanrhys
Hi Guys, We had a series of events that meant our SUFs were unable to forward to their respective indexers for about...
by tristanrhys New Member in Getting Data In 08-24-2015
0 3
0
3
ManishaAgrawal
Hi all, We have set property phoneHomeIntervalInSecs to 1 hour in deploymentclient.conf and pushed this app to forw...
by ManishaAgrawal Explorer in Getting Data In 08-24-2015
1 2
1
2
Splunk_Shinobi
universalforwarderからindexerにデータを転送している環境で、host情報等をもとに保存先のIndexを分ける方法を教えて下さい。 例えば、以下をUniversalforwarder上に設定するとすべてのデータ...
by Splunk_Shinobi Splunk Employee Splunk Employee in Getting Data In 08-24-2015
0 1
0
1
shyam_prabhakar
We are generating inputs.conf configs programmatically with puppet or chef. We have a directory tree with a bunch of...
by shyam_prabhakar New Member in Getting Data In 08-24-2015
0 1
0
1
Abilan1
Hi , I would like to know, is there any way to stop the indexing if any specific source file grows 1 GB in size. Som...
by Abilan1 Path Finder in Getting Data In 08-24-2015
0 4
0
4
brent_weaver
Good morning. I am wondering what filesystem and fs options people are using for spunk indexers? I am running it on C...
by brent_weaver Builder in Getting Data In 08-24-2015
0 1
0
1
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...