| Thread Info | |||||
|---|---|---|---|---|---|
|
Where do I go & how should I do it?
I know what to change,
[$sourcetype] MAX_EVENT = 100000
I would appreci...
by
minkyuk
Explorer
in
Getting Data In
07-07-2015
|
0
|
7
| |||
|
I have some very large lookup tables for known bad domains.(4m+ entries)
the lookup has a field called 'kap_chk' ...
by
borgy95
Path Finder
in
Getting Data In
07-07-2015
|
0
|
3
| |||
|
Hi,
I have cisco ASA and cisco ISE syslogs coming to splunk on udp1026 port. I would like to differentiate the sou...
by
kpsajin
Explorer
in
Getting Data In
06-29-2015
|
0
|
9
| |||
|
Our application had a defect in a logging interceptor that led to a field being duplicated in an event but where both...
by
barrysvee
New Member
in
Getting Data In
07-01-2015
|
0
|
5
| |||
|
In my inputs.conf file, I have an entry for a sourcetype that I want to change.
Currently, it monitors the path: /...
by
Splunkster45
Communicator
in
Getting Data In
06-26-2015
|
0
|
4
| |||
|
I have configured Windows logs input to a certain index Index_test_03, but very few data - tens - go there. Most of t...
by
altink
Builder
in
Getting Data In
07-02-2015
|
0
|
10
| |||
|
Below is the log:
qCode="SOME_CODE", qValue="[{"id":null,"dayStart":"08:00","dayEnd":"18:00","dayOfWeek":"2",...
by
swatijha
New Member
in
Getting Data In
07-03-2015
|
0
|
4
| |||
|
Hi,
I'm stumped. I've been playing with the linebreaking trying to get the format properly, and it won't work. The...
by
a212830
Champion
in
Getting Data In
02-08-2012
|
0
|
15
| |||
|
Just noticed I have a duplicate GUID for two standalone, load balanced (via splunk conf, not F5) indexers. Can I just...
by
davebo1896
Communicator
in
Getting Data In
07-01-2015
|
0
|
1
| |||
|
In my screenshot, you can see my events have duplicate fields. I am trying to figure out why this is occurring. The s...
by
bnorthway
Path Finder
in
Getting Data In
07-06-2015
|
3
|
3
| |||
|
I set up a small network using virtualbox and I am now having trouble forwarding data to the host. The laptop I am us...
by
syx093
Communicator
in
Getting Data In
07-06-2015
|
0
|
1
| |||
|
I have a shared search head used by different groups where those groups have set up their own indexers. They want to ...
by
mjones414
Contributor
in
Getting Data In
06-24-2015
|
0
|
2
| |||
|
Hi,
I'm trying to stop forwarding _audit index. I put in my outputs.conf the following lines:
[tcpout]
forwarde...
by
jeromep83
Engager
in
Getting Data In
07-06-2015
|
0
|
1
| |||
|
I want to add a field extracttion to props.conf that will extract a portion of the uri field to create a custom field...
by
borgy95
Path Finder
in
Getting Data In
07-02-2015
|
0
|
2
| |||
|
How can I configure splunk to index or accept the datestamp in the name of directories? The events only have time sta...
by
suhprano
Path Finder
in
Getting Data In
05-15-2012
|
0
|
1
| |||
|
Hi,
I extracted from the default source field, in search-time, a new field called 'domain': | rex field=source "^(...
by
skender27
Contributor
in
Getting Data In
07-03-2015
|
0
|
9
| |||
|
Hello,
I use a Splunk heavy forwarder and I would like to send inputs to a remote a server.
I have two channels...
by
jeromep83
Engager
in
Getting Data In
07-05-2015
|
2
|
5
| |||
|
I'm indexing a CSV that appears like the following in its raw form:
Filenum,string
1,abc
2,defg
2,abc
3,xyz
3,abc
...
by
jtsplunk
Splunk Employee
in
Getting Data In
04-11-2012
|
0
|
4
| |||
|
Hi,
I'm trying to search a multiline event from a windows server. I need to find out which changes was made with a...
by
krusty
Contributor
in
Getting Data In
04-25-2012
|
0
|
1
| |||
|
I get the feeling this is going to be a tough one to solve, but, I'm trying to aggregate results of a search based up...
by
howyagoin
Contributor
in
Getting Data In
04-13-2012
|
1
|
1
| |||
|
The transform works and filters out the the matching line from going into the index but I still get these errors:
...
by
pshumate
Explorer
in
Getting Data In
03-26-2012
|
0
|
1
| |||
|
I need to apply a lookup only to events before a certain point in time (the data added by the lookup is now included ...
by
Shtark
Explorer
in
Getting Data In
03-28-2012
|
0
|
1
| |||
|
I have a cluster of 4 indexers. The search head sends scheduled scans which always end up draining resources on one ...
by
Aixia
Engager
in
Getting Data In
07-02-2015
|
0
|
2
| |||
|
I've tried to run this..
./splunk cmd python fill_summary_index.py -app search -name "summary" -et 06/14/2015:08:0...
by
lanilim16
Explorer
in
Getting Data In
07-03-2015
|
0
|
1
| |||
|
I have a universal forwarder installed in a few servers and I also have added the logs to be monitored for each. I'm ...
by
lanilim16
Explorer
in
Getting Data In
06-30-2015
|
0
|
7
|