Thread Info | |||||
---|---|---|---|---|---|
I want to know if its possible in props.conf to create one stanza for multiple sourcetypes that doesn't use regex.
...
by
michael_kushma
Path Finder
in
Getting Data In
04-10-2015
|
0
|
1
| |||
I have a single search that stores many events (~500,000) on the same timestamp. As I understood, splunk chunks the ...
by
marcokrueger
Path Finder
in
Getting Data In
04-15-2015
|
0
|
1
| |||
My Splunk partition is filling, due to one file...
/opt/splunk/var/lib/splunk/rscache.data
...this file contai...
by
some_guy
Path Finder
in
Getting Data In
05-11-2015
|
0
|
1
| |||
HI,
I am having following xml log which has two seperate tags for Date and time. I want to use Date + Time togethe...
by
vganjare
Builder
in
Getting Data In
02-05-2015
|
1
|
3
| |||
Hi,
I'm somewhat new to setting up the free Splunk, but have been playing with it and am super impressed so far. U...
by
demondo
Engager
in
Getting Data In
04-12-2015
|
0
|
3
| |||
My apologies if this is elementary... I know the following snippet from my JSON log file is not structurally sound bu...
by
kmcarrol
Path Finder
in
Getting Data In
05-12-2015
|
0
|
2
| |||
Splunk is missing some of the events listed in my syslog file.
(Can't really believe this hasn't been asked. I sea...
by
dlems
Engager
in
Getting Data In
11-22-2010
|
2
|
1
| |||
Hi.
I'm currently trying to get the stack trace in C# in one event, not in multiple events. Please look at the att...
by
Saasen
New Member
in
Getting Data In
05-11-2015
|
0
|
8
| |||
I'm running Splunk 6.2.2 on a Windows Platform. I have 3 Windows domains and would like to send wineventlog:security ...
by
AndreaEClark
Explorer
in
Getting Data In
05-11-2015
|
0
|
3
| |||
Hi,
I am trying to manage the universal forwarders on all our Windows system using the deployment server. They all...
by
mjesudasan
New Member
in
Getting Data In
05-01-2015
|
0
|
1
| |||
hi, I have a monitored directory that is indexed by splunk. I tried removing the files in the directory after they ar...
by
michael_lee
Path Finder
in
Getting Data In
05-12-2015
|
0
|
1
| |||
I have data in the following: host=ICSPSD instId=0001 ptime=2015-05-06 14:41:46,323 modName=icsfront logType=app ip=1...
by
dovelsh12223621
Path Finder
in
Getting Data In
05-06-2015
|
0
|
4
| |||
Hello,
I am writing a modular input in Java. What actually happens when someone presses the "Disable" button on th...
by
akorzun
Explorer
in
Getting Data In
05-11-2015
|
0
|
2
| |||
I am continuously indexing data from CSV file. Events only have time stamp without date. Splunk has automatically ext...
by
atifshaukat
New Member
in
Getting Data In
07-17-2012
|
0
|
4
| |||
I tried to configure a custom datetime.xml (for my first time) as follow:
<datetime>
<define name="csdate" extrac...
by
bizza
Path Finder
in
Getting Data In
05-05-2014
|
1
|
9
| |||
I am trying to extract two separate timestamp formats from a single log file. Here is a sample of the logfile:
[16...
by
mookiie2005
Communicator
in
Getting Data In
03-24-2015
|
0
|
2
| |||
I would like to request some information.
My customer has a big interest in Splunk Enterprise. The company has bee...
by
kwonx149
Engager
in
Getting Data In
05-11-2015
|
0
|
1
| |||
I am setting up splunk universal forwarder on a windows server 2012 R2 in a fully automated manner. I have been able ...
by
rajindersingh
Explorer
in
Getting Data In
05-10-2015
|
0
|
4
| |||
I have a timestamp in %Y%m format - not ideal. Here is an event:
A 201301 08433
The timestamp here...
by
himynamesdave
Contributor
in
Getting Data In
05-06-2015
|
0
|
5
| |||
Hi Everyone,
I have run into a problem I am not able to easily solve with Splunk. I have splunk query that returns...
by
nspatel
Explorer
in
Getting Data In
05-11-2015
|
0
|
2
| |||
Hi, I am expanding from a single server install to 2 servers, each identical with half the index data on each (odd & ...
by
JabawokJayUK
Engager
in
Getting Data In
05-11-2015
|
0
|
5
| |||
Currently, my preProd environment is set up to monitor logs from 100-150 servers with the monitor stanza in inputs.co...
by
JoeSco27
Communicator
in
Getting Data In
05-11-2015
|
0
|
1
| |||
I am looking for a way to modify the default CSV name "splunk-results.csv" in version 6.2.1. I need the CSV attachmen...
by
zindain24
Path Finder
in
Getting Data In
02-27-2015
|
0
|
4
| |||
Hello All,
I am writing a modular input in Java. It streams events in xml format. The example:
<event> <time>13...
by
akorzun
Explorer
in
Getting Data In
05-08-2015
|
0
|
2
| |||
Hi, I wish to exclude certain events not to forward to indexer, as below. How to configure that? thks & rgds
........
by
newbiesplunk
Path Finder
in
Getting Data In
05-11-2015
|
0
|
2
|