| Hi, I have added a data input that uses variables as the host name, so /opt/mark/home/.../.../logs It uses segment 5 ... by markthompson Builder in Getting Data In 10-06-2014 1 1 | 1 | 1 | ||
| Got a lot of logged events in the _internal-index for one of our indexers. First we always see an event like this 02... by rune_hellem Contributor in Getting Data In 10-06-2014 3 9 | 3 | 9 | ||
| We have installed a universal forwarder on a DC. In order to reduce the size of the windows logs indexed, we have us... by aferchichi New Member in Getting Data In 10-06-2014 0 1 | 0 | 1 | ||
| Hey, Is there an event in splunkd.log which identifies when a stanza defined in inputs.conf which is not disabled is... by Ant1D Motivator in Getting Data In 10-06-2014 0 3 | 0 | 3 | ||
| Docs make it look like CHECK_METHOD = endpoint_md5 in props.conf should tell Splunk to only sends deltas. But anytim... by stu2 Explorer in Getting Data In 10-05-2014 0 2 | 0 | 2 | ||
| I am new to splunk. We found some challenging issue with splunk. we imported some logs as files and directories data ... by ginger8990 Explorer in Getting Data In 10-05-2014 0 2 | 0 | 2 | ||
| As title, Is there a way to list all the reports using one specific sourcetype or index? by benjaminlin1019 Explorer in Getting Data In 10-04-2014 0 1 | 0 | 1 | ||
| Hey everyone, I am trying to use Splunk to monitor and index multiple CSVs in a directory (e.g. log1.csv / log2.csv ... by ryanng New Member in Getting Data In 10-04-2014 0 1 | 0 | 1 | ||
| Hi guys, i just want to know the default delimiter for multivalue field in splunk when i export a table to a csv.fil... by gfs2277 New Member in Getting Data In 10-04-2014 0 1 | 0 | 1 | ||
| Hi All, I created the new splunk server and found that the forwarder is only send the latest log to the new server. ... by chrismok Path Finder in Getting Data In 10-04-2014 0 1 | 0 | 1 | ||
| The following is one event of the data: MACUL DIRP101 JUL14 00:00:00 5577 INFO DIRP_FLOW_LOG REASON= 15 SSYS#= 2... by fvasquezchacon Path Finder in Getting Data In 10-03-2014 0 10 | 0 | 10 | ||
| Can someone please explain to me why the Splunk Universal Forwarder uses port 8089 and what problems would arise if I... by rabel001 Explorer in Getting Data In 10-02-2014 3 10 | 3 | 10 | ||
| We have a new Splunk server. We have installed the universal forwarder on the server and it is currently sending the ... by oldguard911 Explorer in Getting Data In 10-02-2014 0 8 | 0 | 8 | ||
| I currently am running splunk enterprise on a Linux Distribution (Red Hat). I am following the guide to import WMI d... by smvalois Explorer in Getting Data In 10-02-2014 1 6 | 1 | 6 | ||
| Hello, Looking to forward data from one indexer to a second indexer. The are multiple reasons for the separate index... by jstaley Explorer in Getting Data In 10-02-2014 1 2 | 1 | 2 | ||
| Hi All, Is there a way to add multiple values in a drop down to a single choice? For example, I have a drop down wi... by _gkollias Builder in Getting Data In 10-02-2014 2 1 | 2 | 1 | ||
| Hi, When i do the data preview, it stated "Failed to parse timestamp, defaulting to file modetime". The correct times... by newbiesplunk Path Finder in Getting Data In 10-02-2014 0 2 | 0 | 2 | ||
| Occasionally, our Windows terminal servers kill the UF service during shutdown, leaving in a stale .pid file behind. ... by martin_mueller SplunkTrust 1 10 | 1 | 10 | ||
| Hello Splunkers, I created a (index-time) field extraction with the following regex: REGEX = ^\d+;\d{11}02(\d{5})\... by mikeschneider Explorer in Getting Data In 10-01-2014 0 5 | 0 | 5 | ||
| Good morning, i'm new to Splunk and have a question regarding universal forwarder deployment. I installed the UF on ... by dersa Path Finder in Getting Data In 10-01-2014 0 1 | 0 | 1 | ||
| I can't seem to find a definitive answer anywhere if it was possible to do this, or if not, why? When I attempt to m... by ntguru5 New Member in Getting Data In 10-01-2014 0 3 | 0 | 3 | ||
| Hi, I'm trying to index a directory, that has subdirectories in this format: -Directory ---Sub Directory ... by markthompson Builder in Getting Data In 10-01-2014 1 4 | 1 | 4 | ||
| By installing Splunk universal forwarder in my linux/Windows server , will it reduce its performance? by srikrishna1011 New Member in Getting Data In 10-01-2014 0 1 | 0 | 1 | ||
| I have a small development environment with one search head and two indexers. I've noticed that the two indexers are ... by lampert_marksu Explorer in Getting Data In 10-01-2014 1 5 | 1 | 5 | ||
| Hi, I have a report that log results for multiple IDs from 2 different SourceType. I need to find out if the report... by Lictor New Member in Getting Data In 10-01-2014 0 3 | 0 | 3 |