Thread Info | |||||
---|---|---|---|---|---|
Is there a way to check and see if a forward is actively forwarding?
For example, at one point splunk add forward-...
by
bauron
Explorer
in
Getting Data In
06-06-2012
|
0
|
1
| |||
I see that the source file splunkd.log is logging excessively. When I look into the diagnostics, I find that my searc...
by
mike7860
Explorer
in
Getting Data In
12-17-2012
|
0
|
7
| |||
Hi,
I have been looking for information about REST API point to know if UF has completed reading the file and send...
by
melonman
Motivator
in
Getting Data In
02-25-2013
|
0
|
2
| |||
Hi,
I am trying to extract multiple occurrences of two fields from the statistics message that is generated by sys...
by
brettw10
Explorer
in
Getting Data In
02-24-2013
|
0
|
2
| |||
Hi all,
I have an application that needs to write some data that may be several levels deep and I'm struggling to ...
by
Tim
Explorer
in
Getting Data In
07-16-2010
|
0
|
2
| |||
Hi All, Please let me know to which source or sourcetype the _geo field belongs to? I want this for second search que...
by
shri_27
Path Finder
in
Getting Data In
02-22-2013
|
0
|
1
| |||
I need to be able to calculate the time difference between two dates and everytime i try anything...it returns blank ...
by
testAnalysis
Explorer
in
Getting Data In
02-22-2013
|
0
|
1
| |||
Hi All,
Trying to filter on Win Sec events, dropping events that don't have particular eventids and Account Name c...
by
only4luca
New Member
in
Getting Data In
10-13-2012
|
0
|
4
| |||
Hi, scenario: a log uploader application helps in uploading logs to a directory. let it be splunkdata/timeofupload/yo...
by
smolcj
Builder
in
Getting Data In
02-22-2013
|
0
|
6
| |||
Hi Splunk experts, I am using regex transform to mask data in splunk. But splunk only masks first occurence of string...
by
vaibhavagg2006
Communicator
in
Getting Data In
02-21-2013
|
0
|
5
| |||
Hi,
I'm trying to set timestamp recognition for a sourcetype, in order to avoid recognising timestamp in the event...
by
echalex
Builder
in
Getting Data In
09-21-2012
|
0
|
3
| |||
I just turned on a splunk forwarder with the active directory monitoring on my AD server. Since the windows logs WinE...
by
yannK
Splunk Employee
in
Getting Data In
02-21-2013
|
3
|
1
| |||
I need to come up with a way to monitor files via UNC (I know this is not the preferred way) for ~140 servers that ar...
by
ShaneNewman
Motivator
in
Getting Data In
02-20-2013
|
0
|
1
| |||
I have currently one Splunk server who works as indexer and searcher. I want to add second server which will be a mir...
by
bckq
Path Finder
in
Getting Data In
10-21-2012
|
0
|
5
| |||
Is it possible to deploy an app from the Splunk master node /master-app/cluster/local to all the peer nodes ?
by
ssankeneni
Communicator
in
Getting Data In
12-05-2012
|
2
|
4
| |||
I have a requirement where in order for the remote machine to send data over the TCP connection to Splunk, it needs S...
by
rohitgupta
New Member
in
Getting Data In
02-20-2013
|
0
|
1
| |||
Hello,
I'm new in splunk. Splunk with syslog works correct now. I try test netflow from cisco asa. I set netflow i...
by
popo80
New Member
in
Getting Data In
02-18-2013
|
0
|
1
| |||
This is a common issue with the syslog sourceytype. By default it behave differently from the other inputs, the host ...
by
yannK
Splunk Employee
in
Getting Data In
02-20-2013
|
2
|
1
| |||
Using [monitor://path] Stanza i need to monitor a folder which contains binary data. When i set the props.conf as,
...
by
chimbudp
Contributor
in
Getting Data In
02-20-2013
|
0
|
3
| |||
I would like to monitor assembly folder in windows. Path :- C: \Windows \assembly
I have set the inputs.conf in Un...
by
chimbudp
Contributor
in
Getting Data In
02-18-2013
|
0
|
8
| |||
Hi,
Ive been playing with the SEDCMD in my props.conf to anonymize CC data in a log.
Originally I tried this:...
by
doreno
Explorer
in
Getting Data In
02-19-2013
|
0
|
11
| |||
I want to index only specific fields like error status in an event and discard the rest. How do I set splunk to do th...
by
pdash
Path Finder
in
Getting Data In
02-18-2013
|
0
|
3
| |||
I know that you can control the Universal Forwarder to grab historical event logs from Windows using "current_only = ...
by
vragosta
Path Finder
in
Getting Data In
02-19-2013
|
0
|
2
| |||
Anyone know why 5.0.1 UFs are reporting data in with host name of $decideonstartup. Looks like this setting was added...
by
dchodur
Path Finder
in
Getting Data In
01-29-2013
|
1
|
6
| |||
I need to monitor the Assembly folder in Windows Server : [monitor://C:\Windows\assembly] index=Assembly_monitor
t...
by
chimbudp
Contributor
in
Getting Data In
02-19-2013
|
0
|
4
|