Getting Data In

Getting Data In
Community Activity
msacks
I am trying to find the top ten Apache errors based on the error message. Error message or message isn't a default f...
by msacks Explorer in Getting Data In 08-31-2013
1 6
1
6
ocallender
Hi folks, I've searched for an answer to this but haven't found anything that matches what I'm experiencing. For cla...
by ocallender Explorer in Getting Data In 08-30-2013
0 1
0
1
cthacker
I've tried a bunch of different things on my Forwarder to get it to watch 2 different paths, and blacklist one folder...
by cthacker Explorer in Getting Data In 08-29-2013
0 3
0
3
fk319
I am missing logs. My logs rotate faster than 5 minutes, anywhere greater than 1 min. It seems that every 5 minutes...
by fk319 Builder in Getting Data In 08-29-2013
0 5
0
5
krugger
Hi, I have the lea-loggrabber.sh script correctly pulling data via OPSEC from multiple firewalls. However my logs ar...
by krugger Communicator in Getting Data In 08-29-2013
2 3
2
3
jonbalderston
I have a lookup which works, it's not matched to a field, it has to search in the raw event. [|inputlookup MyFile.csv...
by jonbalderston Explorer in Getting Data In 08-29-2013
1 4
1
4
avitallange
I have a log file with traces of the format: [source name] [level] [id]: [Time] [trace message] Splunk auto identifi...
by avitallange Explorer in Getting Data In 08-29-2013
0 1
0
1
juniormint
I have a dedicated machine for my splunk forwarder configuration deployment server. I would like to send the deploym...
by juniormint Communicator in Getting Data In 08-29-2013
0 1
0
1
msn2507
Hi all, my input.conf is : [monitor:///Users/user1/log.txt] disabled = false followTail = 1 sourcetype = log_test01 ...
by msn2507 Path Finder in Getting Data In 08-28-2013
0 7
0
7
65pony
We have a very strange file where the first line has hundreds of \x00 values. ex. the following times 50.... \x00\x0...
by 65pony Explorer in Getting Data In 08-28-2013
0 3
0
3
daniel_splunk
I've configured the Check Point OPSEC LEA and the connection is fine. State is enabled. When I do a search with sourc...
by daniel_splunk Splunk Employee Splunk Employee in Getting Data In 08-28-2013
1 1
1
1
juniormint
I'm using the configuration deployment server to manage a bunch of forwarders. One of the apps that they get has inp...
by juniormint Communicator in Getting Data In 08-28-2013
0 7
0
7
cwl
CLIで「splunk search "index=_internal | table _raw" -output csv -maxout 10」のように「-output csv」を使う場合、「_raw」の内容が表示されるが、「spl...
by cwl Contributor in Getting Data In 08-28-2013
0 1
0
1
theeven
Hi folks, Given: In my search I am using stats values() at some point. I am not sure, but this is making me loose tr...
by theeven Explorer in Getting Data In 08-28-2013
0 4
0
4
brettw10
Say I have a UF set up to monitor a file – let’s call it /var/log/syslog-stats.log – which rotates every day (syslog-...
by brettw10 Explorer in Getting Data In 08-28-2013
1 1
1
1
echojacques
My main Splunk index is near it's max size (~500GB). Instead of filtering out more data (nullQueue) I'd like to look...
by echojacques Builder in Getting Data In 08-28-2013
0 3
0
3
rakesh_498115
Hi. I have a common log path in my server say logs/project1/ which has perflogs and debuglogs i.e like this Appt_Per...
by rakesh_498115 Motivator in Getting Data In 08-28-2013
0 1
0
1
nbk7e9d
Hello, When I restart a large application with hundreds of processes, I can see a string like "startup successful" f...
by nbk7e9d New Member in Getting Data In 08-28-2013
0 4
0
4
egruenter
I created a data input on Port 514/UDP and the data goes to an index called "cisco_ironport_wsa" and I set the source...
by egruenter New Member in Getting Data In 08-28-2013
0 3
0
3
Will_Hayes
How do I install and configure the Splunk for Cisco IronPort Web Appliance app on Splunkbase? http://www.splunkbase.c...
by Will_Hayes Splunk Employee Splunk Employee in Getting Data In 08-28-2013
2 5
2
5
hheile
Hi Folks, i have some trouble with importing historical data to splunk. From the manual: splunk_app_2.0_for_wsa_g...
by hheile New Member in Getting Data In 08-28-2013
0 1
0
1
ashleyherbert
Hi All, We have a fleet of AIX & Linux servers running the Universal forwarder, and we have issues with the forwarder...
by ashleyherbert Communicator in Getting Data In 08-27-2013
0 3
0
3
roller
Hello all, I have been having some issues with Splunk indexing events from a particular log with a time in the futur...
by roller New Member in Getting Data In 08-27-2013
0 1
0
1
rferrante
For demo purposes, I plan to set up a single box (all-in-one) instance of Splunk and would like to configure Splunk s...
by rferrante New Member in Getting Data In 08-27-2013
0 2
0
2
mookiie2005
We have data that comes into UDP port 514 on a heavy forwarder that we than send to our indexers. The data looks lik...
by mookiie2005 Communicator in Getting Data In 08-27-2013
0 2
0
2
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...
Top Solution Authors