| Thread Info | |||||
|---|---|---|---|---|---|
| 
        Hi there I want to log information to understand if my application is heavily used on desktop or mobile or tablet..!!...
        
         
           by 
           
                
                    
                        jipatel83
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               06-09-2015
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        About 
  The log file is overwritten each time, therefore the MUST_NOT_BREAK_AFTER in the current definition does wor...
        
         
           by 
           
                
                    
                        rune_hellem
                    
                
           
             
             
               Contributor
             
           
           in
           Getting Data In
           
           
              
               10-20-2014
             
           
         
        | 
		
		2
   | 
	  
	  4
	 | |||
| 
        I'm having a problem right now where I'm not seeing an even distribution across my indexers. I have 21 indexers (inde...
        
         
           by 
           
                
                    
                        rjdargi
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               08-14-2014
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hi all, 
  We have realised recently that one of our application logs is missing a large number of events. This was e...
        
         
           by 
           
                
                    
                        alekksi
                    
                
           
             
             
               Communicator
             
           
           in
           Getting Data In
           
           
              
               06-04-2015
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Hi all, 
  Recently we performed a Disaster Recovery switchover. It was found out after the switchover that none of t...
        
         
           by 
           
                
                    
                        alekksi
                    
                
           
             
             
               Communicator
             
           
           in
           Getting Data In
           
           
              
               02-09-2015
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        I want to change the NIC that the Splunk Universal Forwarder communicates and sends data through if the server has mu...
        
         
           by 
           
                
                    
                        DPWSplunkPOC
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               06-10-2015
             
           
         
        | 
		
		3
   | 
	  
	  1
	 | |||
| 
        Hi,  
  I'm trying to forward /var/log/anaconda/syslog from my linux machine to my splunk indexer, but it's not comin...
        
         
           by 
           
                
                    
                        qazwsxedc994
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               06-10-2015
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        1、日志是以时间开头的,比如:00:11:12:471,也就是当天零点11分12秒471毫秒,可是,splunk识别的时间为15/06/11 2:00 00 000 该怎么办? 
  2、如下的一行,事实上不是一条新的记录,只是上一条...
        
         
           by 
           
                
                    
                        wangyong_2
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               06-10-2015
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hi, 
  My requirement is to match two fields of csv file and get value of third field. I have student name and roll n...
        
         
           by 
           
                
                    
                        ektasiwani
                    
                
           
             
             
               Communicator
             
           
           in
           Getting Data In
           
           
              
               06-09-2015
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Splunk was installed and run as root. I did a "splunk enable boot-start" which created a /etc/init.d/splunk script. U...
        
         
           by 
           
                
                    
                        tony_luu
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               06-08-2015
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        My Help Desk relies upon using the Splunk server to assist with identifying the source machine or BYOD for account lo...
        
         
           by 
           
                
                    
                        AndreaEClark
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               06-02-2015
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Hi, 
  I need to setup a props for an event with the following format. Not certain what to put for "Z" (or if it's ne...
        
         
           by 
           
                
                    
                        a212830
                    
                
           
             
             
               Champion
             
           
           in
           Getting Data In
           
           
              
               06-09-2015
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        I have one indexer and would like to add another indexer for redundancy. Is it possible to cluster the two together a...
        
         
           by 
           
                
                    
                        molinarf
                    
                
           
             
             
               Communicator
             
           
           in
           Getting Data In
           
           
              
               06-05-2015
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        hi, 
  i have some mainframe logs coming into splunk which is in PSV (pipe separated value) format. have managed to p...
        
         
           by 
           
                
                    
                        shivarpith
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               06-09-2015
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        After making a change to my props.conf TIME_FORMAT and SHOULD_LINEMERGE attribute (multiple events started merging to...
        
         
           by 
           
                
                    
                        JoeSco27
                    
                
           
             
             
               Communicator
             
           
           in
           Getting Data In
           
           
              
               06-09-2015
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I am getting to the point where I have quite a few Universal Forwarders in my Splunk infrastructure. I was wondering ...
        
         
           by 
           
                
                    
                        nce054
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               06-09-2015
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        I have a Splunk 6.2.0 multisite cluster setup. Per site, there is one indexer, one search head and a master. I am pul...
        
         
           by 
           
                
                    
                        afmohamm
                    
                
           
             
             
               Engager
             
           
           in
           Getting Data In
           
           
              
               06-09-2015
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I have a strange case where we see more logs in Splunk from the Checkpoint App than the ones in the Checkpoint log se...
        
         
           by 
           
                
                    
                        theouhuios
                    
                
           
             
             
               Motivator
             
           
           in
           Getting Data In
           
           
              
               07-23-2014
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        I've changed the outputs.conf file on my Universal Forwarder to direct to a different server, and restarted the servi...
        
         
           by 
           
                
                    
                        nce054
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               06-08-2015
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hello, 
  For security reasons, I have to monitor processes, especially the IExplore Process. Open connections are im...
        
         
           by 
           
                
                    
                        nicolay_koecher
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               06-09-2015
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hi everyone, 
  My everyday process is to upload logs to splunk web and take a report and analyse it. 
  So in this, ...
        
         
           by 
           
                
                    
                        sahoo0233
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               06-04-2015
             
           
         
        | 
		
		0
   | 
	  
	  22
	 | |||
| 
        We have ~50 hosts that are placed on various locations outside our data center. To receive logs from these hosts we h...
        
         
           by 
           
                
                    
                        sjovang
                    
                
           
             
             
               Engager
             
           
           in
           Getting Data In
           
           
              
               06-09-2015
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I am trying to set up searchable scripts however when i am on my indexer and go to add data and select forwarders it ...
        
         
           by 
           
                
                    
                        qazwsxedc994
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               06-08-2015
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hi, 
  I installed and configured Hunk to read data from HDFS. 
  I'm trying to use Universal Forwarder to write dire...
        
         
           by 
           
                
                    
                        alessio23
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               06-08-2015
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I am a new user trying Splunk for the first time. I am trying to visualize some csv files so we have trending informa...
        
         
           by 
           
                
                    
                        niiick
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               06-05-2015
             
           
         
        | 
		
		0
   | 
	  
	  15
	 |