| Hi, I am trying to analyze the json file for some reason it is not getting indexed. Here is a sample json file [ {<!-- --> ... by htsvaggar New Member in Getting Data In 02-27-2015 0 4 | 0 | 4 | ||
| props.conf has a boolean setting called "pulldown_type". If you set it to true, then the name of your sourcetype will... by sideview SplunkTrust 4 2 | 4 | 2 | ||
| In the process of migrating to an indexes app instead of fixed /opt/splunk/etc/system/local/indexes.conf, I did a sea... by cevyn Explorer in Getting Data In 02-27-2015 0 1 | 0 | 1 | ||
| I am trying to extract timestamp. But instead of 2007, Splunk is extracting 2013 which is not at all in my event. Co... by satishsdange Builder in Getting Data In 02-26-2015 0 1 | 0 | 1 | ||
| Can use a REST API command to identify saved searches using a summary index? by philip_wong Communicator in Getting Data In 02-26-2015 0 2 | 0 | 2 | ||
| I have an index "eng_1" that has a max size of 500,000 MB. When I look in SplunkOnSplunk it reports this index to be... by BradL Path Finder in Getting Data In 02-26-2015 0 3 | 0 | 3 | ||
| Hi, Has anybody done parsing JSON file. If you can let me know what are the setting being done in input.conf and... by htsvaggar New Member in Getting Data In 02-25-2015 0 3 | 0 | 3 | ||
| I am trying to index Security Data from a remote location using the configuration below, but it nothing is getting in... by rbal_splunk Splunk Employee 1 2 | 1 | 2 | ||
| We are inputting JSON fields to splunk. One of the fields eventTime should be the event time for the index. { br... by akhanVG Path Finder in Getting Data In 02-25-2015 1 10 | 1 | 10 | ||
| I'm very curious to hear how other admins are handling summary indexing with multiple indexers and search heads. Sch... by twinspop Influencer in Getting Data In 02-25-2015 0 7 | 0 | 7 | ||
| Hi: I know it is possible for Splunk to read data from a file, but I just had some questions that I need to be addre... by mmohiuddin Path Finder in Getting Data In 02-25-2015 0 15 | 0 | 15 | ||
| I created a folder on our dev Splunk server, and then copied over 12 .gz files (from our radius server). As a test, ... by jwalzerpitt Influencer in Getting Data In 02-25-2015 0 15 | 0 | 15 | ||
| I would like to be able to send Log A to Indexer A and Log B to Indexer B from one forwarder. by zbumpers New Member in Getting Data In 02-25-2015 0 1 | 0 | 1 | ||
| index=audit /collect earliest=-300d [inputlookup serials2check | fields serial | multikv fields serial | rename seria... by TobiasBoone Communicator in Getting Data In 02-25-2015 1 5 | 1 | 5 | ||
| Hi, In the Splunk App I am working on , there is a need to specify some parameters through UI, persist them and late... by klausJohan Path Finder in Getting Data In 02-25-2015 0 4 | 0 | 4 | ||
| A while ago we have deployed about a 1000+ Universal Forwarder over our network, not knowing about deployment server.... by gnoellbn Explorer in Getting Data In 02-25-2015 0 3 | 0 | 3 | ||
| Hi, I would like to know if anyone is running Splunk Indexer on encripted HDD by BitLocker in Windows? Not recomme... by melonman Motivator in Getting Data In 02-25-2015 2 3 | 2 | 3 | ||
| Setting on QNAP is just 4 below. 1 enable syslog 2 configure destination (splunk) server IP address 3 UDP port: 514 ... by 05500 New Member in Getting Data In 02-25-2015 0 5 | 0 | 5 | ||
| Splunk installs on the server and I run the following commands, splunk edit user admin –password At this point I ... by kferden0 New Member in Getting Data In 02-24-2015 0 1 | 0 | 1 | ||
| I've setup a search, and configured Splunk to run a Perl script generating an SNMP message to another system when the... by DTERM Contributor in Getting Data In 02-24-2015 1 5 | 1 | 5 | ||
| Hi, i would like to document and control my splunk deployment configuration, do you have some idea on how to get ... by Ed_Alias Path Finder in Getting Data In 02-24-2015 0 10 | 0 | 10 | ||
| I am using an intermediary server (server 2) to collect forwarded logs from many servers (server 3,4,5,etc) and then ... by cchitten Path Finder in Getting Data In 02-24-2015 0 4 | 0 | 4 | ||
| I have riverbed 10.10.10.1 and barracuda 10.10.10.2 both writing syslog (on UDP 514 which I cannot change) to my Splu... by 7070ithelpdesk New Member in Getting Data In 02-24-2015 0 4 | 0 | 4 | ||
| I upgraded from 6.1.4 to 6.2 for the server and the universal forwarders. Afterwards there are duplicate entries on ... by larrymagstadt Explorer in Getting Data In 02-23-2015 1 15 | 1 | 15 | ||
| Sample Log Data: 20150121 1 101834 10:18:34:794 2953 1 CN0010001 HARI1 GROUP.DEBIT.INT 1 I 150121101834794 How s... by splunk47 New Member in Getting Data In 02-23-2015 0 4 | 0 | 4 |