| Thread Info | |||||
|---|---|---|---|---|---|
| 
        Can someone help me out to get some sample ASA 8.1 & 8.2 log messages.
        
         
           by 
           
                
                    
                        eldhose
                    
                
           
             
             
               Engager
             
           
           in
           Getting Data In
           
           
              
               05-10-2010
             
           
         
        | 
		
		1
   | 
	  
	  1
	 | |||
| 
        I used to have 2 UDP syslog data inputs: UDP://514 going to the default index, UDP://515 going to a new index. They w...
        
         
           by 
           
                
                    
                        lmarcel
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               11-07-2013
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        I'm trying to add a new linemerge rule to my props.conf. I'm currently putting it in etc/system/local/props.conf but ...
        
         
           by 
           
                
                    
                        stevennoble
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               11-08-2013
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I have events that end and start with : 
  orderLock;null; 2013-11-07 05:55:38.431; Log entry...... 162405913;; 2013-...
        
         
           by 
           
                
                    
                        smudge797
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               11-07-2013
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        I guess the title says it all. 
  In general I want to know if there's any way of sending all Windows Event logs thro...
        
         
           by 
           
                
                    
                        drberg
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               11-08-2013
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hi,  I have a search with two lookups ... | lookup user_agent_filter OUTPUT botstatus | lookup ipnet_filter cidr AS i...
        
         
           by 
           
                
                    
                        marcokrueger
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               11-07-2013
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hi All, 
  I have a splunk Indexer receiving data from Kiwi syslog installed on a Splunk Forwarder machine. it also r...
        
         
           by 
           
                
                    
                        rawatvineet
                    
                
           
             
             
               Engager
             
           
           in
           Getting Data In
           
           
              
               11-06-2013
             
           
         
        | 
		
		0
   | 
	  
	  15
	 | |||
| 
        Hi All 
  We currently have splunk installed, and have a fleet of cisco devices feeding syslog to it. This includes: ...
        
         
           by 
           
                
                    
                        CeJay
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               05-13-2013
             
           
         
        | 
		
		0
   | 
	  
	  10
	 | |||
| 
        I have an automated process running on a Windows server that has the Universal Forwarder installed. It drops files fo...
        
         
           by 
           
                
                    
                        JeremyHagan
                    
                
           
             
             
               Communicator
             
           
           in
           Getting Data In
           
           
              
               11-06-2013
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        I am experiencing an issue where my universal forwarder (v5.0.4) is not forwarding my IIS Advanced Logs to the indexe...
        
         
           by 
           
                
                    
                        DaClyde
                    
                
           
             
             
               Contributor
             
           
           in
           Getting Data In
           
           
              
               11-05-2013
             
           
         
        | 
		
		1
   | 
	  
	  15
	 | |||
| 
        I'm having a hard time setting up forwarding and event times. Here's my situation. I have an application that creates...
        
         
           by 
           
                
                    
                        OldManEd
                    
                
           
             
             
               Builder
             
           
           in
           Getting Data In
           
           
              
               11-06-2013
             
           
         
        | 
		
		0
   | 
	  
	  13
	 | |||
| 
        I have an issue where we have a sourcetype that we want to remove a transform (on the indexer) that drops some data (...
        
         
           by 
           
                
                    
                        adylent
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               11-06-2013
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I have a new windows install and I can only get one syslog to show up. Any other devices I direct to send their logs ...
        
         
           by 
           
                
                    
                        slacknetter
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               11-07-2013
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        Hi.. 
  I am trying to find the custom script which emails the conents of the search results specific to the users. I...
        
         
           by 
           
                
                    
                        rakesh_498115
                    
                
           
             
             
               Motivator
             
           
           in
           Getting Data In
           
           
              
               11-07-2013
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Universal forwarder, can a Splunk 5.0.5 forwarder forward to Splunk 6.0 indexer?
        
         
           by 
           
                
                    
                        somesoni2
                    
                
           
             
             
               Revered Legend
             
           
           in
           Getting Data In
           
           
              
               11-07-2013
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Greetings everyone. We have a moderately sized distributed deployment. We have 3 search heads pooled, and all 3 have ...
        
         
           by 
           
                
                    
                        msarro
                    
                
           
             
             
               Builder
             
           
           in
           Getting Data In
           
           
              
               11-05-2013
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        I'm trying to grab the number value of all failed logons on windows logs (eventually will be failed logons per accoun...
        
         
           by 
           
                
                    
                        hagjos43
                    
                
           
             
             
               Contributor
             
           
           in
           Getting Data In
           
           
              
               11-06-2013
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        I have the following config in outputs.conf for splunk forwarder installed on a linux machine. 
  connectionTimeout =...
        
         
           by 
           
                
                    
                        dtekas
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               11-06-2013
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Does anyone have any examples of regex used in the Blacklist patterns for distsearch.conf? We are trying to limit wha...
        
         
           by 
           
                
                    
                        ride76
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               04-19-2012
             
           
         
        | 
		
		1
   | 
	  
	  1
	 | |||
| 
        I have a SOAP output file that I want to do metrics on in Splunk. There is a lot of data in the envelope that is usel...
        
         
           by 
           
                
                    
                        Lazarix
                    
                
           
             
             
               Communicator
             
           
           in
           Getting Data In
           
           
              
               10-30-2013
             
           
         
        | 
		
		0
   | 
	  
	  8
	 | |||
| 
        When initially set up my splunk install is set to capture only the most recent version of a log: 
  /path/to/log/dir/...
        
         
           by 
           
                
                    
                        tyronetv
                    
                
           
             
             
               Communicator
             
           
           in
           Getting Data In
           
           
              
               11-06-2013
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hi, still learning Splunk and.....need to know.. How to delete an "source type" that is tied to indexed data. I accid...
        
         
           by 
           
                
                    
                        nitin82pandey
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               10-25-2013
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        I collect my data using UniveralForwarder, them send it to HeavyForwarder. 
  I would like to send a copy of data tha...
        
         
           by 
           
                
                    
                        fabiocaldas
                    
                
           
             
             
               Contributor
             
           
           in
           Getting Data In
           
           
              
               10-31-2013
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        In the indexing process, which happens first the SEDCMD-* entries or TRANSFORMS-* entries?
        
         
           by 
           
                
                    
                        Lowell
                    
                
           
             
             
               Super Champion
             
           
           in
           Getting Data In
           
           
              
               08-30-2010
             
           
         
        | 
		
		3
   | 
	  
	  2
	 | |||
| 
        I'm trying to figure out how to configure the forwarders to auto load balance. 
  I saw this: http://www.splunk.com/b...
        
         
           by 
           
                
                    
                        msvoboda
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               05-28-2010
             
           
         
        | 
		
		0
   | 
	  
	  3
	 |