| Is there any way to move log data to another index after it has already been indexed? Example.. Windows logs were... by JHill Explorer in Getting Data In 11-25-2014 2 3 | 2 | 3 | ||
| If I find something worth keeping I would like to be able to archive the specific event logs that I want and save the... by aywong Path Finder in Getting Data In 11-25-2014 0 3 | 0 | 3 | ||
| It's very pain to re-enter username/password when we have almost 100 search peers. by philip_wong Communicator in Getting Data In 11-25-2014 1 6 | 1 | 6 | ||
| It would be nice to just click a button in a dashboard, or use a custom search command to be talk to the universal fo... by neiljpeterson Communicator in Getting Data In 11-24-2014 0 5 | 0 | 5 | ||
| I have configured the logs in the inputs.conf and added the servers in the serverclass.conf. Preliminary testing done... by erwinpastor Explorer in Getting Data In 11-24-2014 0 7 | 0 | 7 | ||
| I have 2 indexers setup and have the forwarders set to both of them in outputs.conf. It was my understanding that th... by hlarimer Communicator in Getting Data In 11-24-2014 0 5 | 0 | 5 | ||
| I have a set of input scripts that are working as expected. The problem I am facing is that I need to index the resul... by lpolo Motivator in Getting Data In 11-24-2014 0 7 | 0 | 7 | ||
| I have indexes configured with volumes and started to see this warning after upgrade to 6.* 10-16-2013 18:18:20.951 ... by yannK Splunk Employee 3 8 | 3 | 8 | ||
| I have some computing antiques running Unix; I need to monitor some files on them, and get them into Splunk. I read ... by wegscd Contributor in Getting Data In 11-24-2014 0 8 | 0 | 8 | ||
| After I restore the archived data in thawed path and rebuild the index - Splunk recognizes the data. What is the lif... by splunker12er Motivator in Getting Data In 11-23-2014 0 1 | 0 | 1 | ||
| index=main sourcetype="WinEventLog:Security" EventCode=4624 |stats count by Account_Name by mcronkrite Splunk Employee 0 1 | 0 | 1 | ||
| I am trying to understand what I should expect to see regarding the volume of data I ingest into SPLUNK and its volum... by garryclarke Path Finder in Getting Data In 11-22-2014 0 1 | 0 | 1 | ||
| I'm getting events that show sources as the hosts, but Splunk is indicating that the simple hostname and the FQDN are... by cdyates New Member in Getting Data In 11-22-2014 0 1 | 0 | 1 | ||
| Looking for suggestions for the obvious that I might have overlooked as to why a UF config distributed by Deployment ... by grijhwani Motivator in Getting Data In 11-22-2014 0 5 | 0 | 5 | ||
| I had one of my indexers go down a couple weeks back. Since then each of my forwarders is trying to send events to t... by nocostk Communicator in Getting Data In 11-21-2014 4 4 | 4 | 4 | ||
| Hello, I am trying to create a dashboard or a search to be able to view the current connections on our IIS servers. ... by eziemer New Member in Getting Data In 11-21-2014 0 11 | 0 | 11 | ||
| Say you are running a 6.1 indexer. Can you upgrade the forwarders to 6.2 versions without upgrading the indexer? by sysadm1n New Member in Getting Data In 11-21-2014 0 1 | 0 | 1 | ||
| i need to add the path below to my inputs.conf file and it has a lot of .xml files `/ibuapps/sales/2014-11-11//*.xml... by brod_geico Path Finder in Getting Data In 11-21-2014 0 3 | 0 | 3 | ||
| Hi, I below is the inputs.conf which i have configured on my indexer, but it is not blocking anything. is this is co... by kpavan Path Finder in Getting Data In 11-21-2014 0 6 | 0 | 6 | ||
| Hi splunkers, I just want to ask for any recommended or even tested loadbalancer upon forwarding logs to 3 indexers.... by sympatiko Communicator in Getting Data In 11-21-2014 0 7 | 0 | 7 | ||
| Hi Splunkers, I know about we are able to limit network traffic between Peer (a.k.a. Indexer )and Universal Forward... by sunrise Contributor in Getting Data In 11-21-2014 1 5 | 1 | 5 | ||
| how to fix this error , "WARN TcpOutputProc - Forwarding to indexer group GSOC blocked for 9500 seconds". I cant rec... by tiny3001 Path Finder in Getting Data In 11-21-2014 0 1 | 0 | 1 | ||
| Hi, Good day splunkers. Is it the possible to forward Fortigate logs to multiple indexers via forwarders?, I already... by sympatiko Communicator in Getting Data In 11-21-2014 0 1 | 0 | 1 | ||
| Hi all, I've got a new set of logs from one of our development teams for some in-house applications. They have writt... by javiergn Super Champion in Getting Data In 11-20-2014 1 7 | 1 | 7 | ||
| Hi, It seems log file contains CTRL-M character will cause duplicate parsing in splunk indexer so I would like to fil... by shangshin Builder in Getting Data In 11-20-2014 0 10 | 0 | 10 |