| I went through the Exploring Splunk book which states that the data is indexed w.r.t. _time, host , source & sourceTy... by mohitab Path Finder in Getting Data In 11-17-2014 0 7 | 0 | 7 | ||
| I want to freeze all data older than 90 days. My /opt/splunk/etc/system/local/indexes.conf file looks like this [de... by rblalock New Member in Getting Data In 11-17-2014 0 2 | 0 | 2 | ||
| Hi, i want to forward files from the storage instead of from the local drives, what would be the solution? thks by newbiesplunk Path Finder in Getting Data In 11-17-2014 0 2 | 0 | 2 | ||
| Hi , We have apache access logs generated in below format . access.log_2014.11.11 , access.log_2014.11.12 , ac... by danishdanish1 New Member in Getting Data In 11-17-2014 0 1 | 0 | 1 | ||
| I tried adding the data through inputs.conf. I am trying to add sample log file from my system to the splunk server. ... by vaishnavi07 Explorer in Getting Data In 11-17-2014 0 20 | 0 | 20 | ||
| Hi splunkers, Good day! I have a clustered setup of RF=3 and SF=3. I'm just curious, what if one of my indexers need... by sympatiko Communicator in Getting Data In 11-16-2014 1 6 | 1 | 6 | ||
| According to Splunk's documentation for props.conf, the ANNOTATE_PUNCT setting "Determines whether to index a special... by mthierbel Explorer in Getting Data In 11-16-2014 0 1 | 0 | 1 | ||
| I am facing problem with timestamp from xml file entry. Following is the sample tag from xml file <row Id="82949" U... by v2k007 Engager in Getting Data In 11-16-2014 0 3 | 0 | 3 | ||
| I have a ticket in with support but this may be faster. My intermediate forwarder is not working right. When I rest... by hartfoml Motivator in Getting Data In 11-15-2014 1 3 | 1 | 3 | ||
| I followed the following steps while while upgrading from Splunk 6.1.4 to 6.2, but the Forwarder Inputs section under... by cdo_splunk Splunk Employee 1 1 | 1 | 1 | ||
| Hi, Just a newbie here. Im planning to have a RF=3 SF=3 clustered setup with 5GB on a raid 10 a day volume running. ... by sympatiko Communicator in Getting Data In 11-14-2014 1 2 | 1 | 2 | ||
| Hi Splunkers, I have a strange problem with Microsoft TMG, Splunk can't find the time stamp on one particular event... by btiggemann Path Finder in Getting Data In 11-14-2014 0 2 | 0 | 2 | ||
| Hi there, We have a Windows Heavy Forwarder which gets Windows logs. We want to send these logs to an external Rsysl... by feliz New Member in Getting Data In 11-14-2014 0 2 | 0 | 2 | ||
| Hi everybody, I need to set up a system monitor that collects logon and logout data from some Windows machines (serve... by alessandromagri New Member in Getting Data In 11-13-2014 0 3 | 0 | 3 | ||
| I have seen somewhat similar issues on here, but none that meet my situation. I have a directory on a Windows server... by peter_gianusso Communicator in Getting Data In 11-13-2014 0 4 | 0 | 4 | ||
| Hallo, I am in the need of anonymizing the second column in a tab-separated log file. I use the method described in ... by keywork Explorer in Getting Data In 11-13-2014 0 5 | 0 | 5 | ||
| Hello Experts, We have a field xyz which holds mac addresses. Problem is, some of the mac addresses are of xx:xx:xx:x... by Raghav2384 Motivator in Getting Data In 11-13-2014 1 10 | 1 | 10 | ||
| Hello, I'm having a hard time finding a way forwarding all the internal logs from my Deployment server to the Index ... by santiagoaloi Path Finder in Getting Data In 11-13-2014 0 1 | 0 | 1 | ||
| Hi, I have applied NullQ and IndexQ filtering on my log files at Heavy Forwarder. But the client demands, we do not ... by meenal901 Communicator in Getting Data In 11-13-2014 0 2 | 0 | 2 | ||
| I have created an index called prod_syslog with four sourcetypes monitoring the below paths. I see this app is deplo... by pete_charlton Explorer in Getting Data In 11-13-2014 0 3 | 0 | 3 | ||
| I have a Linux server that forwards data (no local indexing) and also acts as a search head with two Windows search p... by gawman Explorer in Getting Data In 11-12-2014 0 2 | 0 | 2 | ||
| I need to apply CRCsalt for only few file under dir/folder not all of them. Below is my current inputs.conf [monitor... by brod_geico Path Finder in Getting Data In 11-12-2014 0 1 | 0 | 1 | ||
| Here's a puzzler for you all. I have SharePoint search logs coming in. The results field has a value like this: 4##1... by feickertmd Communicator in Getting Data In 11-12-2014 0 6 | 0 | 6 | ||
| I am trying to configure Splunk to index IIS failedrequests. My priority is To have Splunk indexing the Event- tags... by rune_hellem Contributor in Getting Data In 11-12-2014 1 1 | 1 | 1 | ||
| Running windows 2008 64bit , simply wanted to upgrade as it was prompting me too and got annoying so I did now it's b... by mldeschenes Explorer in Getting Data In 11-12-2014 0 4 | 0 | 4 |