Thread Info | |||||
---|---|---|---|---|---|
Today I have change configuration of forwarder and restarted it, after restart it is forwarding previous events as we...
by
moohkhol
New Member
in
Getting Data In
04-02-2014
|
0
|
2
| |||
I am attempting to recover from a hard crash, through no fault of Splunk's. Is it possible to unzip /rawdata/journal....
by
gregwilliams
Path Finder
in
Getting Data In
08-15-2012
|
0
|
3
| |||
[test_header]
INDEXED_EXTRACTIONS = CSV
HEADER_FIELD_LINE_NUMBER = 1
KV_MODE = none
NO_BINARY_CHECK = 1
SHOULD_LINEME...
by
Parameshwara
Path Finder
in
Getting Data In
03-30-2014
|
0
|
10
| |||
I have a modular input that collects data from a webservice. The events are not collected in realtime so to get the t...
by
jedatt01
Builder
in
Getting Data In
04-01-2014
|
0
|
6
| |||
Hi,
I have some data extracted from a table in an SQL database which has 39 columns and uses a semicolon as a fiel...
by
jlaverick1
New Member
in
Getting Data In
04-01-2014
|
0
|
4
| |||
The forwarding from this directory was working previous to the clean. My understanding was this was supposed to clean...
by
neiljpeterson
Communicator
in
Getting Data In
04-01-2014
|
0
|
9
| |||
I have a log file that is tab delimited. It has a field called "date" and a field called "time" next to each other. T...
by
aelliott
Motivator
in
Getting Data In
03-31-2014
|
0
|
11
| |||
Hello, I would like to sent to nullQueue some windows security events based on some regex. So I have defined:
prop...
by
danilom
Explorer
in
Getting Data In
03-31-2014
|
0
|
2
| |||
I have set up a Data input in Splunk which allows me to search a series of CSV files conatined within this folder. Ea...
by
ncorby
New Member
in
Getting Data In
03-20-2014
|
0
|
4
| |||
Due to some error, i had deleted the test123 indexes at indexer, restart the indexer, create the test123 again. But s...
by
SplunkCSIT
Communicator
in
Getting Data In
03-31-2014
|
0
|
5
| |||
I am trying to do this: Universal Forwarder1--> TCP 9997 --> Universal Forwarder2--> TCP 9997 --> Indexer (Search Hea...
by
nikhilmehra79
Path Finder
in
Getting Data In
03-31-2014
|
0
|
2
| |||
Good evening, I have a question: I have a sourcetype A with a field "ip" and a "name" I have a sourcetype B with a f...
by
RichPierre
Engager
in
Getting Data In
03-31-2014
|
0
|
4
| |||
Hey I am trying to put data into my splunk using the TCP option and splunk is asking for my tcp port but I dont know ...
by
athannie92
New Member
in
Getting Data In
04-01-2014
|
0
|
1
| |||
I have been trying to grab results from a macro that i created. I think the problem is the backticks, even when i esc...
by
Face_it
New Member
in
Getting Data In
03-31-2014
|
0
|
2
| |||
At random I am getting a strange heavy forwarder issue that no one seems to have received before (google comes up wit...
by
ifeldshteyn
Communicator
in
Getting Data In
12-06-2013
|
2
|
8
| |||
I have configured the index.conf homePath = C:\DB\index1\db thawedPath = C:\DB\index1\thaweddb frozenTimePeriodInSecs...
by
tararso
Explorer
in
Getting Data In
03-31-2014
|
0
|
1
| |||
I realized the other day we are no longer seeing instances of $decideonstartup in the host field for some of our logs...
by
Runals
Motivator
in
Getting Data In
03-29-2014
|
0
|
1
| |||
I have a large archive of old data i want to load while also loading new real-time data.
What is the most efficie...
by
Erik_Swan
Splunk Employee
in
Getting Data In
03-29-2010
|
2
|
5
| |||
Hi
I have a load of warnings in splunkd.log like:
06-15-2011 09:02:23.860 +0100 WARN DateParserVerbose - A pos...
by
craigmunro
Path Finder
in
Getting Data In
06-15-2011
|
0
|
6
| |||
Hello, friends!
We have: Splunk server (indexer) and computer with WinXP and UniversalForwarder. The task was to r...
by
templier
Communicator
in
Getting Data In
01-22-2014
|
1
|
9
| |||
Hi I am able to send log4j log data to splunk over tcp network but the data in splunk is not human readable.(see belo...
by
shangshin
Builder
in
Getting Data In
06-21-2012
|
2
|
1
| |||
I am sending data to a TCP port I configured for input on the Splunk server. How should the (string) data be encoded ...
by
helge
Builder
in
Getting Data In
03-31-2014
|
0
|
1
| |||
how come when i configured the data in the heavy forwarder, sometimes it will created in launcher folder /etc/apps/la...
by
SplunkCSIT
Communicator
in
Getting Data In
03-29-2014
|
0
|
3
| |||
現在Splunk6.0.2に対して、curlコマンドで直接JSONデータを入力できないかと試しています。 TCP:10000をtcp-rawポートに設定しています。
curl -X POST -d 'json={"tag":"v...
by
t_nakayama
Engager
in
Getting Data In
03-10-2014
|
1
|
2
| |||
Can we forward logs to two different indexer, if it a manual task such that to change at the inputs.conf and outputs....
by
SplunkCSIT
Communicator
in
Getting Data In
03-27-2014
|
0
|
4
|