| I am trying to do this: Universal Forwarder1--> TCP 9997 --> Universal Forwarder2--> TCP 9997 --> Indexer (Search Hea... by nikhilmehra79 Path Finder in Getting Data In 04-01-2014 0 2 | 0 | 2 | ||
| Good evening, I have a question: I have a sourcetype A with a field "ip" and a "name" I have a sourcetype B with a f... by RichPierre Engager in Getting Data In 04-01-2014 0 4 | 0 | 4 | ||
| Hey I am trying to put data into my splunk using the TCP option and splunk is asking for my tcp port but I dont know ... by athannie92 New Member in Getting Data In 04-01-2014 0 1 | 0 | 1 | ||
| I have been trying to grab results from a macro that i created. I think the problem is the backticks, even when i esc... by Face_it New Member in Getting Data In 03-31-2014 0 2 | 0 | 2 | ||
| At random I am getting a strange heavy forwarder issue that no one seems to have received before (google comes up wit... by ifeldshteyn Communicator in Getting Data In 03-31-2014 2 8 | 2 | 8 | ||
| I have configured the index.conf homePath = C:\DB\index1\db thawedPath = C:\DB\index1\thaweddb frozenTimePeriodInSecs... by tararso Explorer in Getting Data In 03-31-2014 0 1 | 0 | 1 | ||
| I realized the other day we are no longer seeing instances of $decideonstartup in the host field for some of our logs... by Runals Motivator in Getting Data In 03-31-2014 0 1 | 0 | 1 | ||
| I have a large archive of old data i want to load while also loading new real-time data. What is the most efficient... by Erik_Swan Splunk Employee 2 5 | 2 | 5 | ||
| Hi I have a load of warnings in splunkd.log like: 06-15-2011 09:02:23.860 +0100 WARN DateParserVerbose - A possibl... by craigmunro Path Finder in Getting Data In 03-31-2014 0 6 | 0 | 6 | ||
| Hello, friends! We have: Splunk server (indexer) and computer with WinXP and UniversalForwarder. The task was to rem... by templier Communicator in Getting Data In 03-31-2014 1 9 | 1 | 9 | ||
| Hi I am able to send log4j log data to splunk over tcp network but the data in splunk is not human readable.(see belo... by shangshin Builder in Getting Data In 03-31-2014 2 1 | 2 | 1 | ||
| I am sending data to a TCP port I configured for input on the Splunk server. How should the (string) data be encoded ... by helge Builder in Getting Data In 03-31-2014 0 1 | 0 | 1 | ||
| how come when i configured the data in the heavy forwarder, sometimes it will created in launcher folder /etc/apps/la... by SplunkCSIT Communicator in Getting Data In 03-31-2014 0 3 | 0 | 3 | ||
| 現在Splunk6.0.2に対して、curlコマンドで直接JSONデータを入力できないかと試しています。 TCP:10000をtcp-rawポートに設定しています。 curl -X POST -d 'json={"tag":"val... by t_nakayama Engager in Getting Data In 03-30-2014 1 2 | 1 | 2 | ||
| Can we forward logs to two different indexer, if it a manual task such that to change at the inputs.conf and outputs.... by SplunkCSIT Communicator in Getting Data In 03-30-2014 0 4 | 0 | 4 | ||
| Hi, Running both Splunk server and Splunkforwarder on V6.0.2. Both machine (web server and Splunk server) have their... by thierryit Path Finder in Getting Data In 03-29-2014 0 25 | 0 | 25 | ||
| I am attempting to override the sourcetype of an event that is coming in on UDP:516 based on the host address but I h... by rmcdougal Path Finder in Getting Data In 03-29-2014 0 2 | 0 | 2 | ||
| I have the following entry in my $SPLUNK_HOME/etc/system/local/inputs.conf file -- [monitor:///appl/sharp/logs/*.fip... by romitsn New Member in Getting Data In 03-28-2014 0 1 | 0 | 1 | ||
| I've tried several different configurations and can't seem to get this to work. I have a log file like: "3/23/2014 ... by ngvella Explorer in Getting Data In 03-28-2014 0 2 | 0 | 2 | ||
| Hello, I have the following question. I have in my environment 4 index servers and 2 search head. I also have 2... by italogf Explorer in Getting Data In 03-28-2014 0 2 | 0 | 2 | ||
| I'm running my trial Splunk indexer on a linux host and already collecting data from switches, VMware hosts, firewall... by FloydATC Explorer in Getting Data In 03-28-2014 0 2 | 0 | 2 | ||
| Hi Splunkers! This is less of a question, and more of a (hopefully) handy tip that I hope will answer peoples questi... by rturk Builder in Getting Data In 03-27-2014 0 1 | 0 | 1 | ||
| Hi . I Have my data something like this... SRFR10279A1 R10A1 R0033201 cdain LOW SDEDS1 ... by rakesh_498115 Motivator in Getting Data In 03-27-2014 0 5 | 0 | 5 | ||
| How do I package an app for upload to Splunkbase, especially on Windows where there is no built-in support for creati... by Justin_Grant Contributor in Getting Data In 03-26-2014 1 2 | 1 | 2 | ||
| i did not configure the indexer server properly initially hence the log is indexed locally. After i configured the in... by SplunkCSIT Communicator in Getting Data In 03-26-2014 0 5 | 0 | 5 |