Getting Data In

Getting Data In
Community Activity
msn2507
Hi all, my input.conf is : [monitor:///Users/user1/log.txt] disabled = false followTail = 1 sourcetype = log_test01 ...
by msn2507 Path Finder in Getting Data In 08-28-2013
0 7
0
7
65pony
We have a very strange file where the first line has hundreds of \x00 values. ex. the following times 50.... \x00\x0...
by 65pony Explorer in Getting Data In 08-28-2013
0 3
0
3
daniel_splunk
I've configured the Check Point OPSEC LEA and the connection is fine. State is enabled. When I do a search with sourc...
by daniel_splunk Splunk Employee Splunk Employee in Getting Data In 08-28-2013
1 1
1
1
juniormint
I'm using the configuration deployment server to manage a bunch of forwarders. One of the apps that they get has inp...
by juniormint Communicator in Getting Data In 08-28-2013
0 7
0
7
cwl
CLIで「splunk search "index=_internal | table _raw" -output csv -maxout 10」のように「-output csv」を使う場合、「_raw」の内容が表示されるが、「spl...
by cwl Contributor in Getting Data In 08-28-2013
0 1
0
1
theeven
Hi folks, Given: In my search I am using stats values() at some point. I am not sure, but this is making me loose tr...
by theeven Explorer in Getting Data In 08-28-2013
0 4
0
4
brettw10
Say I have a UF set up to monitor a file – let’s call it /var/log/syslog-stats.log – which rotates every day (syslog-...
by brettw10 Explorer in Getting Data In 08-28-2013
1 1
1
1
echojacques
My main Splunk index is near it's max size (~500GB). Instead of filtering out more data (nullQueue) I'd like to look...
by echojacques Builder in Getting Data In 08-28-2013
0 3
0
3
rakesh_498115
Hi. I have a common log path in my server say logs/project1/ which has perflogs and debuglogs i.e like this Appt_Per...
by rakesh_498115 Motivator in Getting Data In 08-28-2013
0 1
0
1
nbk7e9d
Hello, When I restart a large application with hundreds of processes, I can see a string like "startup successful" f...
by nbk7e9d New Member in Getting Data In 08-28-2013
0 4
0
4
egruenter
I created a data input on Port 514/UDP and the data goes to an index called "cisco_ironport_wsa" and I set the source...
by egruenter New Member in Getting Data In 08-28-2013
0 3
0
3
Will_Hayes
How do I install and configure the Splunk for Cisco IronPort Web Appliance app on Splunkbase? http://www.splunkbase.c...
by Will_Hayes Splunk Employee Splunk Employee in Getting Data In 08-28-2013
2 5
2
5
hheile
Hi Folks, i have some trouble with importing historical data to splunk. From the manual: splunk_app_2.0_for_wsa_g...
by hheile New Member in Getting Data In 08-28-2013
0 1
0
1
ashleyherbert
Hi All, We have a fleet of AIX & Linux servers running the Universal forwarder, and we have issues with the forwarder...
by ashleyherbert Communicator in Getting Data In 08-27-2013
0 3
0
3
roller
Hello all, I have been having some issues with Splunk indexing events from a particular log with a time in the futur...
by roller New Member in Getting Data In 08-27-2013
0 1
0
1
rferrante
For demo purposes, I plan to set up a single box (all-in-one) instance of Splunk and would like to configure Splunk s...
by rferrante New Member in Getting Data In 08-27-2013
0 2
0
2
mookiie2005
We have data that comes into UDP port 514 on a heavy forwarder that we than send to our indexers. The data looks lik...
by mookiie2005 Communicator in Getting Data In 08-27-2013
0 2
0
2
JoeSco27
My Splunk instance had a sourcetype called Netstat (csv format), when I downloaded the *Nix App (which also has a Net...
by JoeSco27 Communicator in Getting Data In 08-27-2013
0 1
0
1
funkyboy
I am trying to upload a > 100Mb file (gzipped is just 17Mb). There is no support for the upload of zipped files. How ...
by funkyboy Engager in Getting Data In 08-27-2013
1 3
1
3
asarolkar
Hi, We were using a system which has a central Splunk head and multiple search peers where the search peers were DIS...
by asarolkar Builder in Getting Data In 08-27-2013
0 4
0
4
torgeirarnoy
Hi, We have a fairly new install of Splunk 5.0.4, and i've now opened UDP:514 and the syslog is flowing in. The prob...
by torgeirarnoy Engager in Getting Data In 08-27-2013
0 2
0
2
luthfi49
Can Splunk Filter data in field level before indexing ? Field level mean that we want to remove some field from even...
by luthfi49 Explorer in Getting Data In 08-27-2013
0 13
0
13
paycorp
Hi, I have a couple of network devices which are sending logs to splunk over udp (so no forwarder installed on them...
by paycorp Engager in Getting Data In 08-27-2013
0 1
0
1
erinhamilton
I have turned this particular Universal Forwarder off ( it is for testing), however I continue to receive WinEvents f...
by erinhamilton Engager in Getting Data In 08-26-2013
0 5
0
5
Ricapar
Part of the configuration we send to all of our Universal Forwarders instructs them to also send along their log file...
by Ricapar Communicator in Getting Data In 08-26-2013
0 1
0
1
Get Updates on the Splunk Community!

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...
Top Solution Authors