Thread Info | |||||
---|---|---|---|---|---|
I have run into a situation where a very large amount of data has been imported into the wrong index. This index cont...
by
kevinzona
Engager
in
Getting Data In
02-01-2012
|
1
|
2
| |||
I have a rather complex saved search that functions perfectly when accessed via the UI. But when a job is kicked off ...
by
emiller42
Motivator
in
Getting Data In
01-31-2012
|
0
|
1
| |||
Hello,
How could we avoid duplicate reporting of the same host?
Hosts (≥ 3) host Count Last Update 1 Testserver...
by
sneuser
New Member
in
Getting Data In
01-31-2012
|
0
|
2
| |||
I have some data in my index that I don't want. How can I get rid of them?
by
the_wolverine
Champion
in
Getting Data In
04-16-2010
|
8
|
4
| |||
I've recently upgraded the forwarder to a universal forwarder on our app server.I'm collecting windows event logs as ...
by
remy06
Contributor
in
Getting Data In
01-09-2012
|
0
|
5
| |||
Hey,
I am looking to add a static field "instance=testdrive" to all results from a source input with td-idp-manage...
by
sonicZ
Contributor
in
Getting Data In
01-26-2012
|
0
|
3
| |||
I haven't seen any conclusive documentation on this, however does the Universal forwarder support Apps like the Splun...
by
ngcgoon
Explorer
in
Getting Data In
05-17-2011
|
1
|
3
| |||
The "active-only" feature doesn't seem to work in Splunk 4.3:
# splunk add monitor /var/log/messages -active-only ...
by
matthewpowell
Engager
in
Getting Data In
01-27-2012
|
1
|
3
| |||
UPDATE: I just downloaded the sourcecode from the SVN repository and made the modification myself and rebuilt the jar...
by
jcott28
Explorer
in
Getting Data In
06-21-2011
|
2
|
1
| |||
Hi,
I've configured a directory for monitoring in inputs.conf ([monitor://path_to_dir]) and separated index for th...
by
Vladimir
Path Finder
in
Getting Data In
01-27-2012
|
0
|
6
| |||
Guys, I currently run splunk on a Windows box. Is it possible for me to move the database from Windows to Linux (Cent...
by
Nik
New Member
in
Getting Data In
04-27-2011
|
0
|
2
| |||
I have the Splunk for Windows app installed but it is collecting syslog UDP:514 data as well. How do I exclude the sy...
by
gharpe2
Explorer
in
Getting Data In
01-27-2012
|
0
|
1
| |||
My Splunk won't start due to this error! What do I do?
ERROR: failed to load index config: 'maxTotalDataSizeMB' ta...
by
Flynt
Splunk Employee
in
Getting Data In
01-27-2012
|
2
|
3
| |||
Hello,
I have several questions/issues with the Splunk API, so I'll try to keep this short and concise.
First -...
by
merritsa
Path Finder
in
Getting Data In
01-25-2012
|
3
|
12
| |||
According to this document: Specifyinputpathswithwildcards
The asterisk wildcard matches anything in that spe...
by
pheezy
Explorer
in
Getting Data In
01-26-2012
|
1
|
3
| |||
Hi All,
Question about reindexing indexed data:
I have a legacy 4.2.x splunk server running. Its set to index a...
by
mark
Path Finder
in
Getting Data In
01-24-2012
|
0
|
2
| |||
We've recently changed out our servers and when I use the searches against these new hosts using my user I am not get...
by
jdibble
Explorer
in
Getting Data In
01-23-2012
|
0
|
7
| |||
So, I've installed and configured the Splunk forward on my Intranet Server. I'm trying to get the IIS logs from \Wind...
by
bherbert
Engager
in
Getting Data In
01-24-2012
|
0
|
3
| |||
Does anyone know how we can use the timestamp of the file from the operating system as the timestamp for events? For ...
by
ngcgoon
Explorer
in
Getting Data In
03-07-2011
|
0
|
4
| |||
We're trying to forward data to a syslog server from a splunk server. However, seems that the hostname and process id...
by
acalvo
Explorer
in
Getting Data In
10-29-2010
|
2
|
6
|