| Splunk is not showing the correct time that logs are coming in. They are behind by five hours. The time on the server... by sbattista09 Contributor in Getting Data In 03-02-2015 1 5 | 1 | 5 | ||
| I create two virtual indexes within Hunk that reads from two separate HDFS directory. One is for Cisco ASA logs, and ... by jwalzerpitt Influencer in Getting Data In 03-02-2015 0 25 | 0 | 25 | ||
| I have a log file with events that look like: < Start > Timestamp: 2/27/2015 8:34:14 PM Information: Message: Refres... by jwinderDDS Path Finder in Getting Data In 03-02-2015 0 2 | 0 | 2 | ||
| A Splunk estate I came across has hundreds of sourcetypes, mostly creating a new sourcetype per different log, regard... by splunk_zen Builder in Getting Data In 03-02-2015 0 2 | 0 | 2 | ||
| What is the frequency with which logs are read in Splunk? Does delay in seeing recent log details in Splunk related t... by garimayadav New Member in Getting Data In 03-01-2015 0 4 | 0 | 4 | ||
| Hi, I wish to monitor linux server info like number of CPU, processor, linux version etc in Splunk. What will be th... by newbiesplunk Path Finder in Getting Data In 03-01-2015 0 1 | 0 | 1 | ||
| I uploaded a .CSV file with 30,000 events into Splunk with currency amount (excel currency format '($1,234.10)'. Usi... by quanteq Path Finder in Getting Data In 02-28-2015 1 10 | 1 | 10 | ||
| Hi All; 3 Drop down inputs right now are being used as a custom timepicker. The first one is used to select any of t... by tdiestel Path Finder in Getting Data In 02-27-2015 1 1 | 1 | 1 | ||
| See this webpage for reference - http://www.timeanddate.com/time/leapseconds.html On June 30 2012, an extra second w... by mctester Communicator in Getting Data In 02-27-2015 4 2 | 4 | 2 | ||
| What are the things that you normally do as part of a Splunk server installation? David Carasso published a nice lis... by lguinn2 Legend in Getting Data In 02-27-2015 1 6 | 1 | 6 | ||
| Hi, I am trying to analyze the json file for some reason it is not getting indexed. Here is a sample json file [ {<!-- --> ... by htsvaggar New Member in Getting Data In 02-27-2015 0 4 | 0 | 4 | ||
| props.conf has a boolean setting called "pulldown_type". If you set it to true, then the name of your sourcetype will... by sideview SplunkTrust 4 2 | 4 | 2 | ||
| In the process of migrating to an indexes app instead of fixed /opt/splunk/etc/system/local/indexes.conf, I did a sea... by cevyn Explorer in Getting Data In 02-27-2015 0 1 | 0 | 1 | ||
| I am trying to extract timestamp. But instead of 2007, Splunk is extracting 2013 which is not at all in my event. Co... by satishsdange Builder in Getting Data In 02-26-2015 0 1 | 0 | 1 | ||
| Can use a REST API command to identify saved searches using a summary index? by philip_wong Communicator in Getting Data In 02-26-2015 0 2 | 0 | 2 | ||
| I have an index "eng_1" that has a max size of 500,000 MB. When I look in SplunkOnSplunk it reports this index to be... by BradL Path Finder in Getting Data In 02-26-2015 0 3 | 0 | 3 | ||
| Hi, Has anybody done parsing JSON file. If you can let me know what are the setting being done in input.conf and... by htsvaggar New Member in Getting Data In 02-25-2015 0 3 | 0 | 3 | ||
| I am trying to index Security Data from a remote location using the configuration below, but it nothing is getting in... by rbal_splunk Splunk Employee 1 2 | 1 | 2 | ||
| We are inputting JSON fields to splunk. One of the fields eventTime should be the event time for the index. { br... by akhanVG Path Finder in Getting Data In 02-25-2015 1 10 | 1 | 10 | ||
| I'm very curious to hear how other admins are handling summary indexing with multiple indexers and search heads. Sch... by twinspop Influencer in Getting Data In 02-25-2015 0 7 | 0 | 7 | ||
| Hi: I know it is possible for Splunk to read data from a file, but I just had some questions that I need to be addre... by mmohiuddin Path Finder in Getting Data In 02-25-2015 0 15 | 0 | 15 | ||
| I created a folder on our dev Splunk server, and then copied over 12 .gz files (from our radius server). As a test, ... by jwalzerpitt Influencer in Getting Data In 02-25-2015 0 15 | 0 | 15 | ||
| I would like to be able to send Log A to Indexer A and Log B to Indexer B from one forwarder. by zbumpers New Member in Getting Data In 02-25-2015 0 1 | 0 | 1 | ||
| index=audit /collect earliest=-300d [inputlookup serials2check | fields serial | multikv fields serial | rename seria... by TobiasBoone Communicator in Getting Data In 02-25-2015 1 5 | 1 | 5 | ||
| Hi, In the Splunk App I am working on , there is a need to specify some parameters through UI, persist them and late... by klausJohan Path Finder in Getting Data In 02-25-2015 0 4 | 0 | 4 |