| Thread Info | |||||
|---|---|---|---|---|---|
| 
        On an 'All time' range, the two following searches provide different results. The first one gives the expected result...
        
         
           by 
           
                
                    
                        laurent_
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               05-06-2014
             
           
         
        | 
		
		1
   | 
	  
	  4
	 | |||
| 
        Looking to use splunk to compare my cisco router configuration files? Since it does not seem I can use the forwarder ...
        
         
           by 
           
                
                    
                        skibum
                    
                
           
             
             
               Engager
             
           
           in
           Getting Data In
           
           
              
               06-12-2010
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        A certain web host stopped offering AWStats with its hosting. Instead, they point you to Google Webmaster Tools. I us...
        
         
           by 
           
                
                    
                        lonwinters
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               05-08-2014
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        I have set up universal forwarders on our Lync servers to send the WinEventLog:Lync Server events back to the indexer...
        
         
           by 
           
                
                    
                        kmugglet
                    
                
           
             
             
               Communicator
             
           
           in
           Getting Data In
           
           
              
               05-08-2014
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hi,splunkers 
  We want to index multiline log messages with no timestamp as one event. 
  But regular expression for...
        
         
           by 
           
                
                    
                        akanno
                    
                
           
             
             
               Communicator
             
           
           in
           Getting Data In
           
           
              
               05-02-2014
             
           
         
        | 
		
		0
   | 
	  
	  9
	 | |||
| 
        I'm seeing a lot of these WARNs reported by indexer and would like to know what it means: 
   
   03-12-2014 17:57:38...
        
         
           by 
           
                
                    
                        the_wolverine
                    
                
           
             
             
               Champion
             
           
           in
           Getting Data In
           
           
              
               03-12-2014
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I have a windows domain controller with a universal forwarder. I have Splunk_TA_Windows deployed out to it using the ...
        
         
           by 
           
                
                    
                        aelliott
                    
                
           
             
             
               Motivator
             
           
           in
           Getting Data In
           
           
              
               05-06-2014
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        Hi all, 
  I did the following: 
  Set up a splunk forwarderObtained my SplunkStorm CredentialsInstalled splunk crede...
        
         
           by 
           
                
                    
                        SeanKilleen
                    
                
           
             
             
               Engager
             
           
           in
           Getting Data In
           
           
              
               10-11-2013
             
           
         
        | 
		
		0
   | 
	  
	  8
	 | |||
| 
        How do I reclaim my disk space after deleting a large number of events from an index? 
  The Remove data from Splunk ...
        
         
           by 
           
                
                    
                        Lowell
                    
                
           
             
             
               Super Champion
             
           
           in
           Getting Data In
           
           
              
               05-13-2010
             
           
         
        | 
		
		2
   | 
	  
	  5
	 | |||
| 
        Hi I cannot get the universal forwarder to move to active mode. 
  I get the following error in splunkd logs. Can you...
        
         
           by 
           
                
                    
                        RuthBishop
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               05-08-2014
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        hello 
  I am trying to extract a field and change the value of source for apache logs. The source comes as  
  /tmp/...
        
         
           by 
           
                
                    
                        theouhuios
                    
                
           
             
             
               Motivator
             
           
           in
           Getting Data In
           
           
              
               04-30-2014
             
           
         
        | 
		
		0
   | 
	  
	  8
	 | |||
| 
        Hey, 
  I am monitoring some Windows Event Log data and I want to see from this any events where the 'startup type' i...
        
         
           by 
           
                
                    
                        Ant1D
                    
                
           
             
             
               Motivator
             
           
           in
           Getting Data In
           
           
              
               05-08-2014
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I have a network where I have a splunk instance that is off to the side on my network, as in: 
  Core Splunk Instance...
        
         
           by 
           
                
                    
                        jmsiegma
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               04-23-2014
             
           
         
        | 
		
		1
   | 
	  
	  2
	 | |||
| 
        I installed the splunkforwarder on a few machines, and added /var/log as a syslog source. I overlooked the fact that ...
        
         
           by 
           
                
                    
                        tinkster
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               05-06-2014
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        The Splunk software matrix doesn't mentioned support for Windows Server 2012 R2. What versions of Splunk and the Univ...
        
         
           by 
           
                
                    
                        hornslethk
                    
                
           
             
             
               Engager
             
           
           in
           Getting Data In
           
           
              
               12-03-2013
             
           
         
        | 
		
		4
   | 
	  
	  17
	 | |||
| 
        I've run back and forth through the props.conf documentation and done a few circuits of Answers, but I haven't found ...
        
         
           by 
           
                
                    
                        willial
                    
                
           
             
             
               Communicator
             
           
           in
           Getting Data In
           
           
              
               05-07-2014
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Okay, so here is my situation: I am running a Splunk for Window Enterprise Server along with a separate OSSEC server ...
        
         
           by 
           
                
                    
                        ceichhorn
                    
                
           
             
             
               Engager
             
           
           in
           Getting Data In
           
           
              
               05-07-2014
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Is there any capability within Splunk so it automatically deletes the Application, Security, and System Logs in Event...
        
         
           by 
           
                
                    
                        sysadmin74
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               10-11-2011
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        What are the steps to setup a new CA and generate new certs for SSL forwarding with no auth:
        
         
           by 
           
                
                    
                        matt
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Getting Data In
           
           
              
               08-12-2010
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        I am writing a Windows Security Log search for user accounts and have the eventID I need to search for but the result...
        
         
           by 
           
                
                    
                        kluey
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               05-06-2014
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hi Team, 
  I have a folder by name Mumbai under C drive with subfolders in it.  
  If i edit the inputs.conf file as...
        
         
           by 
           
                
                    
                        sushma7
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               05-01-2014
             
           
         
        | 
		
		1
   | 
	  
	  20
	 | |||
| 
        Guys, I'm trying to index some Syslog data from some F5's. The issue I have is, Splunk seems to recognize and break l...
        
         
           by 
           
                
                    
                        salles
                    
                
           
             
             
               Loves-to-Learn Lots
             
           
           in
           Getting Data In
           
           
              
               05-05-2014
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        We are running searchhead pooling and have many indexers. I would like to be able to find out how long it takes for a...
        
         
           by 
           
                
                    
                        rmorlen
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Getting Data In
           
           
              
               04-22-2014
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hi Guys, 
  I'm trying to break events in Splunk with a text file with just ip addresss in it and no time stamps. The...
        
         
           by 
           
                
                    
                        tbalouch
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               05-05-2014
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I am using the DB Connect app to connect to a MYSQL database and input the data from a table. 
  the datetime fields ...
        
         
           by 
           
                
                    
                        hylee
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               12-08-2013
             
           
         
        | 
		
		0
   | 
	  
	  4
	 |