Getting Data In

Getting Data In
Community Activity
shangshin
Hi, It seems log file contains CTRL-M character will cause duplicate parsing in splunk indexer so I would like to fil...
by shangshin Builder in Getting Data In 11-20-2014
0 10
0
10
feickertmd
How can I use Splunk to tell me how much data per day each host is forwarding to Splunk? Basically, I need a report t...
by feickertmd Communicator in Getting Data In 11-20-2014
0 4
0
4
MikhailArefiev
I am trying to split some really long lines we have put in our .conf files using the traditional Unix way of escaping...
by MikhailArefiev Explorer in Getting Data In 11-19-2014
0 5
0
5
sympatiko
Hi, I'm just new with splunk. I'm getting this error upon forwarding my fortigate logs to splunk. How can I set splu...
by sympatiko Communicator in Getting Data In 11-19-2014
0 4
0
4
ruiaires
Sometimes, when troubleshooting inputs on large installations (deployment apps, several layers of forwarders, etc), i...
by ruiaires Path Finder in Getting Data In 11-19-2014
0 1
0
1
saileec
Hi all, I want the "date" field to be used as timestamp. However, in some of the events this field is missing and so...
by saileec Engager in Getting Data In 11-19-2014
0 3
0
3
vonStauf
Based on the documentation provided, the proper command-line arguments to be used when deploying certificates is CERT...
by vonStauf Explorer in Getting Data In 11-19-2014
1 1
1
1
Benlavender
Hello, We’re looking to remove data from one of our indexes, preferably using the clean operator from the CLI. We h...
by Benlavender Explorer in Getting Data In 11-19-2014
0 1
0
1
nitheeshp86
I have configured a universal forwarder on one of our Linux systems. When i check the logs it shows Connection to ho...
by nitheeshp86 New Member in Getting Data In 11-19-2014
0 1
0
1
akshaybahetii
I have unix timestamp in my data file . review/time: 1182816000 review/summary: Periwinkle... To parse this timesta...
by akshaybahetii New Member in Getting Data In 11-18-2014
0 7
0
7
bgaignon
Hi guys, I have a source that send log via syslog push tcp 514. The configuration is working well on my SPlunk test ...
by bgaignon Path Finder in Getting Data In 11-18-2014
0 7
0
7
gnoellbn
Hello, I've read Splunk documentation on that matter but I'm not able to find my answer. Does anyone know how Splunk...
by gnoellbn Explorer in Getting Data In 11-18-2014
0 2
0
2
mohitab
I went through the Exploring Splunk book which states that the data is indexed w.r.t. _time, host , source & sourceTy...
by mohitab Path Finder in Getting Data In 11-17-2014
0 7
0
7
rblalock
I want to freeze all data older than 90 days. My /opt/splunk/etc/system/local/indexes.conf file looks like this [de...
by rblalock New Member in Getting Data In 11-17-2014
0 2
0
2
newbiesplunk
Hi, i want to forward files from the storage instead of from the local drives, what would be the solution? thks
by newbiesplunk Path Finder in Getting Data In 11-17-2014
0 2
0
2
danishdanish1
Hi , We have apache access logs generated in below format . access.log_2014.11.11 , access.log_2014.11.12 , ac...
by danishdanish1 New Member in Getting Data In 11-17-2014
0 1
0
1
vaishnavi07
I tried adding the data through inputs.conf. I am trying to add sample log file from my system to the splunk server. ...
by vaishnavi07 Explorer in Getting Data In 11-17-2014
0 20
0
20
sympatiko
Hi splunkers, Good day! I have a clustered setup of RF=3 and SF=3. I'm just curious, what if one of my indexers need...
by sympatiko Communicator in Getting Data In 11-16-2014
1 6
1
6
mthierbel
According to Splunk's documentation for props.conf, the ANNOTATE_PUNCT setting "Determines whether to index a special...
by mthierbel Explorer in Getting Data In 11-16-2014
0 1
0
1
v2k007
I am facing problem with timestamp from xml file entry. Following is the sample tag from xml file <row Id="82949" U...
by v2k007 Engager in Getting Data In 11-16-2014
0 3
0
3
hartfoml
I have a ticket in with support but this may be faster. My intermediate forwarder is not working right. When I rest...
by hartfoml Motivator in Getting Data In 11-15-2014
1 3
1
3
cdo_splunk
I followed the following steps while while upgrading from Splunk 6.1.4 to 6.2, but the Forwarder Inputs section under...
by cdo_splunk Splunk Employee Splunk Employee in Getting Data In 11-14-2014
1 1
1
1
sympatiko
Hi, Just a newbie here. Im planning to have a RF=3 SF=3 clustered setup with 5GB on a raid 10 a day volume running. ...
by sympatiko Communicator in Getting Data In 11-14-2014
1 2
1
2
btiggemann
Hi Splunkers, I have a strange problem with Microsoft TMG, Splunk can't find the time stamp on one particular event...
by btiggemann Path Finder in Getting Data In 11-14-2014
0 2
0
2
feliz
Hi there, We have a Windows Heavy Forwarder which gets Windows logs. We want to send these logs to an external Rsysl...
by feliz New Member in Getting Data In 11-14-2014
0 2
0
2
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...
Top Solution Authors