Thread Info | |||||
---|---|---|---|---|---|
Hi,
i have a weird problem with forwarding logs from my apache servers to both spunk and a 3rd party syslog server...
by
petergus
New Member
in
Getting Data In
04-10-2014
|
0
|
1
| |||
How often does Splunk check for aged data and reclaim disk space? I reset the frozenTimePeriodInSecs on an indexer fr...
by
OldManEd
Builder
in
Getting Data In
04-11-2014
|
0
|
4
| |||
We have 3 new HP Red Hat Servers we need to install with 13 already running. All of them have 8 drives and the new on...
by
OldManEd
Builder
in
Getting Data In
04-08-2014
|
0
|
1
| |||
I am trying to get the top 10 Failed Login count by User. The problem is that Windows 2008 uses "Account_Name" and Wi...
by
aberdamy
Explorer
in
Getting Data In
04-10-2014
|
0
|
6
| |||
Is there a way to test the performance of sed scripts running in props.conf? I'm not an expert in regular expressions...
by
sc0tt
Builder
in
Getting Data In
04-11-2014
|
0
|
3
| |||
Hi
Which is best format to index for the splunk indexer XML or JSON... what is recommendation from SPlunk like whi...
by
nsiva23
Explorer
in
Getting Data In
04-10-2014
|
0
|
1
| |||
I am trying to setup Splunk to monitor a remote tomcat instance ( catalina.out ) for messages like permGen Running ou...
by
kamal2222ahmed
Explorer
in
Getting Data In
04-10-2014
|
0
|
6
| |||
My index has a retention of 6 months with frozenTimePeriodInSecs=15552000. But I still see some events that are olde...
by
mataharry
Communicator
in
Getting Data In
01-15-2014
|
1
|
2
| |||
All I want to do is create a query that fetches the below result
Day Index-name Volume 4/1 abc 5GB 4/2 abc 8GB 4/3...
by
xbbj3nj
Path Finder
in
Getting Data In
04-10-2014
|
0
|
4
| |||
We just had an application bug that spewed millions of duplicate messages into a Splunk monitored logfile. This cause...
by
genemats
Engager
in
Getting Data In
02-03-2012
|
4
|
3
| |||
Hey all,
I'm able to successfully monitor a log file on a Windows server (2008 R2) using the Universal Forwarder w...
by
gustavomichels
Path Finder
in
Getting Data In
04-10-2014
|
0
|
1
| |||
I'm using a Splunk forwarder to forward data from an application running on the same Linux box as my forwarder.
O...
by
MatMeredith
Path Finder
in
Getting Data In
04-10-2014
|
0
|
1
| |||
Often times, we are tasked with deleting data out of an index to trim it down. Generally, we do this by setting the f...
by
hajducko
Explorer
in
Getting Data In
04-09-2014
|
1
|
5
| |||
Hi,
This is probably very basic, but I'm not sure where the actual log file sits for Windows Event Logs.
Tryin...
by
bcusick
Communicator
in
Getting Data In
04-09-2014
|
0
|
1
| |||
In the Server 2008 Event Viewer there are now a "Microsoft --> Windows" folders nested under the "Applications and Se...
by
kbecker
Communicator
in
Getting Data In
08-30-2010
|
2
|
5
| |||
I have a custom log in the format where each new record has a entry followed by a pipe (|)
example log:
...
by
rileyken
Explorer
in
Getting Data In
04-09-2014
|
0
|
2
| |||
In my props.conf I know I can change: $SPLUNK_HOME/etc/system/local/ and add: [source::xyz123] TZ=US/Eastern or by ho...
by
hagjos43
Contributor
in
Getting Data In
04-08-2014
|
0
|
2
| |||
Hey everyone. I'm wondering how this is possible to accomplish - we have windows server farms across numerous timezo...
by
msarro
Builder
in
Getting Data In
12-06-2013
|
1
|
1
| |||
Hi All,
We have a customer who could not justify the cost of a clustered solution. So they went down the following...
by
phoenixdigital
Builder
in
Getting Data In
04-07-2014
|
0
|
1
| |||
After upgrading my Windows servers 2003 to Splunk 6. I discovered that all my nullQueues filter stopped working, and ...
by
yannK
Splunk Employee
in
Getting Data In
01-13-2014
|
3
|
7
| |||
I want to be able to use the search GUI to create summary index searches, but i want the actual resulting summary ind...
by
tpsplunk
Communicator
in
Getting Data In
07-15-2011
|
1
|
4
| |||
We've installed and are evaluating Splunk Enterprise 6.0 in a Windows environment (desktops are running Windows 7 Pro...
by
kenniskoldewyn
Explorer
in
Getting Data In
03-12-2014
|
1
|
6
| |||
Does anyone know if it is possible to automatically add the current_only = [0|1] attribute in a scripted Universal Fo...
by
aberdamy
Explorer
in
Getting Data In
04-03-2014
|
0
|
3
| |||
We are able to start splunk services - But getting following error while starting the services in Heavy Forwarder
...
by
rbal_splunk
Splunk Employee
in
Getting Data In
04-07-2014
|
0
|
1
| |||
Recently some of our universal forwarders stopped sending events to indexer?
Is there a way to get an alert if for...
by
ajaysamantbms
Explorer
in
Getting Data In
04-07-2014
|
0
|
1
|