| Thread Info | |||||
|---|---|---|---|---|---|
| 
        Just noticed I have a duplicate GUID for two standalone, load balanced (via splunk conf, not F5) indexers. Can I just...
        
         
           by 
           
                
                    
                        davebo1896
                    
                
           
             
             
               Communicator
             
           
           in
           Getting Data In
           
           
              
               07-01-2015
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        In my screenshot, you can see my events have duplicate fields. I am trying to figure out why this is occurring. The s...
        
         
           by 
           
                
                    
                        bnorthway
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               07-06-2015
             
           
         
        | 
		
		3
   | 
	  
	  3
	 | |||
| 
        I set up a small network using virtualbox and I am now having trouble forwarding data to the host. The laptop I am us...
        
         
           by 
           
                
                    
                        syx093
                    
                
           
             
             
               Communicator
             
           
           in
           Getting Data In
           
           
              
               07-06-2015
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I have a shared search head used by different groups where those groups have set up their own indexers. They want to ...
        
         
           by 
           
                
                    
                        mjones414
                    
                
           
             
             
               Contributor
             
           
           in
           Getting Data In
           
           
              
               06-24-2015
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hi, 
  I'm trying to stop forwarding _audit index. I put in my outputs.conf the following lines: 
  [tcpout]
forwarde...
        
         
           by 
           
                
                    
                        jeromep83
                    
                
           
             
             
               Engager
             
           
           in
           Getting Data In
           
           
              
               07-06-2015
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I want to add a field extracttion to props.conf that will extract a portion of the uri field to create a custom field...
        
         
           by 
           
                
                    
                        borgy95
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               07-02-2015
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        How can I configure splunk to index or accept the datestamp in the name of directories? The events only have time sta...
        
         
           by 
           
                
                    
                        suhprano
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               05-15-2012
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hi, 
  I extracted from the default source field, in search-time, a new field called 'domain': | rex field=source "^(...
        
         
           by 
           
                
                    
                        skender27
                    
                
           
             
             
               Contributor
             
           
           in
           Getting Data In
           
           
              
               07-03-2015
             
           
         
        | 
		
		0
   | 
	  
	  9
	 | |||
| 
        Hello, 
  I use a Splunk heavy forwarder and I would like to send inputs to a remote a server. 
  I have two channels...
        
         
           by 
           
                
                    
                        jeromep83
                    
                
           
             
             
               Engager
             
           
           in
           Getting Data In
           
           
              
               07-05-2015
             
           
         
        | 
		
		2
   | 
	  
	  5
	 | |||
| 
        I'm indexing a CSV that appears like the following in its raw form: 
  Filenum,string
1,abc
2,defg
2,abc
3,xyz
3,abc
...
        
         
           by 
           
                
                    
                        jtsplunk
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Getting Data In
           
           
              
               04-11-2012
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Hi, 
  I'm trying to search a multiline event from a windows server. I need to find out which changes was made with a...
        
         
           by 
           
                
                    
                        krusty
                    
                
           
             
             
               Contributor
             
           
           in
           Getting Data In
           
           
              
               04-25-2012
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I get the feeling this is going to be a tough one to solve, but, I'm trying to aggregate results of a search based up...
        
         
           by 
           
                
                    
                        howyagoin
                    
                
           
             
             
               Contributor
             
           
           in
           Getting Data In
           
           
              
               04-13-2012
             
           
         
        | 
		
		1
   | 
	  
	  1
	 | |||
| 
        The transform works and filters out the the matching line from going into the index but I still get these errors: 
  ...
        
         
           by 
           
                
                    
                        pshumate
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               03-26-2012
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I need to apply a lookup only to events before a certain point in time (the data added by the lookup is now included ...
        
         
           by 
           
                
                    
                        Shtark
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               03-28-2012
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I have a cluster of 4 indexers.  The search head sends scheduled scans which always end up draining resources on one ...
        
         
           by 
           
                
                    
                        Aixia
                    
                
           
             
             
               Engager
             
           
           in
           Getting Data In
           
           
              
               07-02-2015
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I've tried to run this.. 
  ./splunk cmd python fill_summary_index.py -app search -name "summary" -et 06/14/2015:08:0...
        
         
           by 
           
                
                    
                        lanilim16
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               07-03-2015
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I have a universal forwarder installed in a few servers and I also have added the logs to be monitored for each. I'm ...
        
         
           by 
           
                
                    
                        lanilim16
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               06-30-2015
             
           
         
        | 
		
		0
   | 
	  
	  7
	 | |||
| 
        How to use POST REST Command in the search to reschedule the saved search scheduled time. 
  for e.g saved search xxx...
        
         
           by 
           
                
                    
                        sbbadri
                    
                
           
             
             
               Motivator
             
           
           in
           Getting Data In
           
           
              
               07-01-2015
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        I have a log file which is written out in XML through Microsoft.Practices.EnterpriseLibrary.ExceptionHandling. I want...
        
         
           by 
           
                
                    
                        Nicolasfm
                    
                
           
             
             
               Engager
             
           
           in
           Getting Data In
           
           
              
               07-03-2015
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        I have a deployment server from where i have a firewall rule that alows me to reach the 8089 management port of all f...
        
         
           by 
           
                
                    
                        dominiquevocat
                    
                
           
             
             
               SplunkTrust
             
           
           in
           Getting Data In
           
           
              
               04-08-2015
             
           
         
        | 
		
		1
   | 
	  
	  3
	 | |||
| 
        Hi, 
  I have a Cassandra database. I want to index historical data as well as real time data that's coming to Cassan...
        
         
           by 
           
                
                    
                        p_gurav
                    
                
           
             
             
               Champion
             
           
           in
           Getting Data In
           
           
              
               06-28-2015
             
           
         
        | 
		
		2
   | 
	  
	  5
	 | |||
| 
        Hi! I'm using Splunk Free, specifically the monitor feature from a directory. I put several files in it, but not all ...
        
         
           by 
           
                
                    
                        fvasquezchacon
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               07-02-2015
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hi there, 
  I'm using a Splunk UF to monitor a Windows folder and syslog the events to a remote server where they ar...
        
         
           by 
           
                
                    
                        someyoungfella
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               12-10-2012
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hi All, 
  I have some log data that includes INFO, WARN, ERROR and DEBUG levels. 
  I would like to index INFO, WARN...
        
         
           by 
           
                
                    
                        gyarici
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               06-26-2015
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Hello, 
  I have a question about indexing multiple types of logs file in same folder. How would go about defining so...
        
         
           by 
           
                
                    
                        sramiz
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               06-25-2015
             
           
         
        | 
		
		0
   | 
	  
	  6
	 |