| Hi, I'm trying to stop forwarding _audit index. I put in my outputs.conf the following lines: [tcpout] forwardedind... by jeromep83 Engager in Getting Data In 07-06-2015 0 1 | 0 | 1 | ||
| I want to add a field extracttion to props.conf that will extract a portion of the uri field to create a custom field... by borgy95 Path Finder in Getting Data In 07-06-2015 0 2 | 0 | 2 | ||
| How can I configure splunk to index or accept the datestamp in the name of directories? The events only have time sta... by suhprano Path Finder in Getting Data In 07-06-2015 0 1 | 0 | 1 | ||
| Hi, I extracted from the default source field, in search-time, a new field called 'domain': | rex field=source "^(\/... by skender27 Contributor in Getting Data In 07-06-2015 0 9 | 0 | 9 | ||
| Hello, I use a Splunk heavy forwarder and I would like to send inputs to a remote a server. I have two channels on ... by jeromep83 Engager in Getting Data In 07-05-2015 2 5 | 2 | 5 | ||
| I'm indexing a CSV that appears like the following in its raw form: Filenum,string 1,abc 2,defg 2,abc 3,xyz 3,abc 1,... by jtsplunk Splunk Employee 0 4 | 0 | 4 | ||
| Hi, I'm trying to search a multiline event from a windows server. I need to find out which changes was made with a f... by krusty Contributor in Getting Data In 07-05-2015 0 1 | 0 | 1 | ||
| I get the feeling this is going to be a tough one to solve, but, I'm trying to aggregate results of a search based up... by howyagoin Contributor in Getting Data In 07-05-2015 1 1 | 1 | 1 | ||
| The transform works and filters out the the matching line from going into the index but I still get these errors: WA... by pshumate Explorer in Getting Data In 07-04-2015 0 1 | 0 | 1 | ||
| I need to apply a lookup only to events before a certain point in time (the data added by the lookup is now included ... by Shtark Explorer in Getting Data In 07-04-2015 0 1 | 0 | 1 | ||
| I have a cluster of 4 indexers. The search head sends scheduled scans which always end up draining resources on one ... by Aixia Engager in Getting Data In 07-03-2015 0 2 | 0 | 2 | ||
| I've tried to run this.. ./splunk cmd python fill_summary_index.py -app search -name "summary" -et 06/14/2015:08:00:... by lanilim16 Explorer in Getting Data In 07-03-2015 0 1 | 0 | 1 | ||
| I have a universal forwarder installed in a few servers and I also have added the logs to be monitored for each. I'm ... by lanilim16 Explorer in Getting Data In 07-03-2015 0 7 | 0 | 7 | ||
| How to use POST REST Command in the search to reschedule the saved search scheduled time. for e.g saved search xxx ... by sbbadri Motivator in Getting Data In 07-03-2015 0 3 | 0 | 3 | ||
| I have a log file which is written out in XML through Microsoft.Practices.EnterpriseLibrary.ExceptionHandling. I want... by Nicolasfm Engager in Getting Data In 07-03-2015 0 3 | 0 | 3 | ||
| I have a deployment server from where i have a firewall rule that alows me to reach the 8089 management port of all f... by dominiquevocat SplunkTrust 1 3 | 1 | 3 | ||
| Hi, I have a Cassandra database. I want to index historical data as well as real time data that's coming to Cassandr... by p_gurav Champion in Getting Data In 07-02-2015 2 5 | 2 | 5 | ||
| Hi! I'm using Splunk Free, specifically the monitor feature from a directory. I put several files in it, but not all ... by fvasquezchacon Path Finder in Getting Data In 07-02-2015 0 1 | 0 | 1 | ||
| Hi there, I'm using a Splunk UF to monitor a Windows folder and syslog the events to a remote server where they are ... by someyoungfella New Member in Getting Data In 07-02-2015 0 1 | 0 | 1 | ||
| Hi All, I have some log data that includes INFO, WARN, ERROR and DEBUG levels. I would like to index INFO, WARN, ER... by gyarici Path Finder in Getting Data In 07-02-2015 0 5 | 0 | 5 | ||
| Hello, I have a question about indexing multiple types of logs file in same folder. How would go about defining sour... by sramiz Path Finder in Getting Data In 07-02-2015 0 6 | 0 | 6 | ||
| Is there a list anywhere of which props.conf settings apply to indexing and which to searching? I'm trying to migrat... by responsys_cm Builder in Getting Data In 07-02-2015 0 3 | 0 | 3 | ||
| Have syslog message with time stamp: <134>1 2014-11-25T18:22:48.720252Z EMM-JimS-01 Splunk search is not showing th... by simpkins1958 Contributor in Getting Data In 07-01-2015 0 5 | 0 | 5 | ||
| I am running the Universal Forwarder on a Windows Server pointed to a linux splunk server. I also have a wmi.conf fi... by techfutures Engager in Getting Data In 07-01-2015 2 1 | 2 | 1 | ||
| Still learning the proper procedure, but which apps can I install on forwarders? I've installed a few on the Splunk... by racurrie New Member in Getting Data In 07-01-2015 0 2 | 0 | 2 |