| Is there a way to use kv_mode=json and remove levels of nesting during indexing or later? Example: we jave some json... by dominiquevocat SplunkTrust 0 2 | 0 | 2 | ||
| Hi , I have custom fonts for my dashboard and added the same in my app in the below path. /opt/splunk/etc/apps/MY_A... by rakesh_498115 Motivator in Getting Data In 07-22-2015 1 2 | 1 | 2 | ||
| We are rebuilding our distributed search Splunk environment: 1 Deployment Server 1 Dedicated Search Head 1 License S... by brent_weaver Builder in Getting Data In 07-22-2015 0 1 | 0 | 1 | ||
| Hi all, I am fairly new to Splunk and have been working on the following search time field extraction to grab window... by maxdessureault Engager in Getting Data In 07-22-2015 0 6 | 0 | 6 | ||
| Hi splunkers, I want to achieve 1 day retention for indexed data. How can I achieve this? I have a cluster setup wit... by sympatiko Communicator in Getting Data In 07-21-2015 0 12 | 0 | 12 | ||
| Hello, This is my code for installing and updating the UniversalForwarder via the command line. msiexec.exe /i "\\s... by timospringer New Member in Getting Data In 07-21-2015 0 2 | 0 | 2 | ||
| We have many systems with Universal Forwarders sending to a dedicated Heavy Forwarder. We would like to put a 3rd par... by kylerose Explorer in Getting Data In 07-21-2015 1 6 | 1 | 6 | ||
| So, here's my admittedly dumb situation. I have an IPAM appliance(s) that does both DNS and DHCP. The output port for... by aaron_schmuhl Engager in Getting Data In 07-21-2015 0 2 | 0 | 2 | ||
| I have a AIX 7.1 machine setup as a forwarder running Splunk 6.1.2. Splunk keeps crashing almost and I need help to f... by edwardman88 Explorer in Getting Data In 07-21-2015 4 4 | 4 | 4 | ||
| Recently my Windows Universal Forwarder stopped forwarding Windows application event log messages to my indexer. See... by peter_gianusso Communicator in Getting Data In 07-21-2015 0 1 | 0 | 1 | ||
| We're looking to substitute the host field, which is an IP address, with the device name that corresponds to the IP a... by papalmi New Member in Getting Data In 07-21-2015 0 5 | 0 | 5 | ||
| Hello all, In a current project, I have to work with an existing Splunk environment which is already in use for abo... by pinVie Path Finder in Getting Data In 07-21-2015 0 3 | 0 | 3 | ||
| New to Splunk so any help is appreciated. I am uploading mytest.log and trying to use SEDCMD to unravel a few fields... by bjensen_splunk New Member in Getting Data In 07-21-2015 0 2 | 0 | 2 | ||
| Hello, one of our application has the following log structure #Fields: Date ; Time ; Site Instance ; Event ; Clie... by abovebeyond Communicator in Getting Data In 07-21-2015 0 4 | 0 | 4 | ||
| How do I wildcard any windows drive letter in the inputs.conf stanza below? inputs.conf [monitor://[A-Z]:\Data\Disk... by archspangler Path Finder in Getting Data In 07-21-2015 0 4 | 0 | 4 | ||
| I read somewhere this is possible, however I can't find where or how - looking for confirmation: Essentially I have ... by LewisWheeler Communicator in Getting Data In 07-21-2015 0 4 | 0 | 4 | ||
| I have downloaded the install file splunkforwarder-6.2.4-271043-SunOS10-sparc.tar.z for a server running solaris10. ... by dhasemore Engager in Getting Data In 07-20-2015 0 3 | 0 | 3 | ||
| Here is the sample data. RED: 2086 GREEN: 1579 WHITE: 159 PINK: 348 ORANGE: 0 by pavan257 New Member in Getting Data In 07-20-2015 0 11 | 0 | 11 | ||
| Hi. I'm brand new to using Splunk and just downloaded the Splunk Light trial. I've followed the tutorial video for... by pcampion New Member in Getting Data In 07-20-2015 0 13 | 0 | 13 | ||
| I created an input in the _json format and send to it httpd access logs. I received such logs: Jul 14 14:35:44 172.1... by vinchakov_a Path Finder in Getting Data In 07-20-2015 0 6 | 0 | 6 | ||
| I have two platforms to monitor. I want to create one application that I can apply to all hosts that come on board. I... by brent_weaver Builder in Getting Data In 07-20-2015 0 1 | 0 | 1 | ||
| inputs.conf [monitor:///home/foo/logs/*/app] whitelist = \.gmt.log$ blacklist = monitor disabled = false Underneat... by pkeller Contributor in Getting Data In 07-20-2015 0 2 | 0 | 2 | ||
| I know that I can create custom source types by adding them to /etc/system/local/props.conf. However, I've created a ... by jfinnig3 Engager in Getting Data In 07-20-2015 0 3 | 0 | 3 | ||
| Hi, I have a field that I want to expand to multiple lines (it's email transactions), so I have a CSV of: source,d... by adolan New Member in Getting Data In 07-20-2015 0 1 | 0 | 1 | ||
| I want to monitor logs kept on a Linux box A, but I do not want to install a Splunk forwarder on box A. a Splunk forw... by ayushchoudhary Path Finder in Getting Data In 07-20-2015 0 1 | 0 | 1 |