| Is there a way to see the originating forwarder for a specfic event? I haven't found any internal/metadata fields. Th... by mikaelbje Motivator in Getting Data In 11-04-2014 0 2 | 0 | 2 | ||
| My environment generates on average about 12GB of logs daily (out of a license for 20GB). The Splunk indexer is gene... by steveirogers Communicator in Getting Data In 11-04-2014 0 3 | 0 | 3 | ||
| I'm loading a file via Data Inputs into Splunk on a daily basis. When I load the file the _time field is the current ... by akelly4 Path Finder in Getting Data In 11-03-2014 2 3 | 2 | 3 | ||
| I would like to configure Splunk to monitor some log files in var/log and when i go to add data and select the direct... by jwalzerpitt Influencer in Getting Data In 11-03-2014 0 2 | 0 | 2 | ||
| Hello, we have what appears to be an incredibly weird scenario going on: We commonly override the serverName for dep... by t9445 Path Finder in Getting Data In 11-03-2014 0 1 | 0 | 1 | ||
| Hi, According to the document splunk should use empty string for non-matching lookup by default. Yet, when i set an ... by dorilevy Path Finder in Getting Data In 11-03-2014 1 1 | 1 | 1 | ||
| Hi, Is this value for the total size of the index apply to this specific server, within a cluster, or within my enti... by a212830 Champion in Getting Data In 11-03-2014 1 1 | 1 | 1 | ||
| I have a silly question. I found this from docs.splunk.com but how do I configure it so that Splunk can get event log... by lain179 Communicator in Getting Data In 10-31-2014 1 4 | 1 | 4 | ||
| Hi, I'm running Splunk 6.1.4 and I send JSON documents through a TCP port. I have a JSON document as follow and no s... by jeanmatthieu Explorer in Getting Data In 10-31-2014 0 1 | 0 | 1 | ||
| Hi, We are collecting Windows logs from a universal forwarder in a Windows Splunk Indexer. Now, I want to collect th... by viverma5 Explorer in Getting Data In 10-31-2014 0 3 | 0 | 3 | ||
| I was wondering if anyone had a way to easily define a serverclass based on the UF version? We are managing our 5 to... by ltrand Contributor in Getting Data In 10-31-2014 0 3 | 0 | 3 | ||
| Using 5.0.2. I am receiving Windows Event Logs at the Indexer from Universal Forwarders on Windows servers. I want to... by mokeefe New Member in Getting Data In 10-31-2014 0 5 | 0 | 5 | ||
| 1 0/21/14 13:17:08.747 SERIAL ZPIMXTerminal.Send Start 10/21/14 13:17:08.747 SERIAL SerialComClass:****NOTICE: Seria... by hemanath_ofc Explorer in Getting Data In 10-31-2014 0 1 | 0 | 1 | ||
| How to remove double quotes from outputlookup csv file by mvaradarajam Path Finder in Getting Data In 10-30-2014 0 1 | 0 | 1 | ||
| Twice a year we have a set of servers used for testing our apps during DST time changes. About 2 months before we wi... by mikelanghorst Motivator in Getting Data In 10-30-2014 0 6 | 0 | 6 | ||
| till now we have been using putty tool to analyze logs locally in windows , but it is very tedious process to check a... by laxmikants Engager in Getting Data In 10-30-2014 0 2 | 0 | 2 | ||
| I have data in the following format (Serv-U ftp log) [5] Sun 01Jun08 00:24:04 - (000555) Connected to 76.76.76.76 (L... by lakromani Builder in Getting Data In 10-29-2014 1 5 | 1 | 5 | ||
| We recently upgraded the Splunk Universal Forwarder to version 6.1.1 on our Domain Controllers. Splunk-winevtlog.exe... by gn694 Communicator in Getting Data In 10-29-2014 0 2 | 0 | 2 | ||
| How are other users utilizing Splunk to monitor privileged account usage in Windows/*nix environments? I'm looking fo... by NateStreet New Member in Getting Data In 10-29-2014 0 1 | 0 | 1 | ||
| I am using Splunk (6.2) deployed on Windows 2008 R2. for some reason the configuration is failing with a "size limi... by caija Engager in Getting Data In 10-29-2014 1 4 | 1 | 4 | ||
| Can we take logs of memory.dmp into splunk in windows? If yes.. how it is possible.. source (%systemRoot%\memory.dmp) by mrabbani New Member in Getting Data In 10-29-2014 0 1 | 0 | 1 | ||
| Dear Community, i would like to import a locally stored .mdb (MS Access) file into splunk. My first intention would ... by jonas_daberkow New Member in Getting Data In 10-28-2014 0 1 | 0 | 1 | ||
| Hello, if you have powershell errors for try and catch keywords for the Citrix TA (or others), you need to upgrade t... by mdessus_splunk Splunk Employee 0 1 | 0 | 1 | ||
| BREAK_ONLY_BEFORE=\d{7} NO_BINARY_CHECK=1 SHOULD_LINEMERGE=true TIME_FORMAT=%3N TIME_PREFIX=\d{7} Trying to parse o... by nitrogaute New Member in Getting Data In 10-28-2014 0 10 | 0 | 10 | ||
| I have a heavy and complicated Enterprise messaging system splunked. The idea is to implement splunk query to logical... by Jayadevanprabha New Member in Getting Data In 10-27-2014 0 1 | 0 | 1 |