Getting Data In

Getting Data In
Community Activity
Strype
Although I personally wouldn't want to set it up this way... Is it possible to have one indexer that works for 2 sep...
by Strype Path Finder in Getting Data In 04-19-2013
0 3
0
3
oranger1426
indexes.conf is set to read only I can't even change my frozenbucket retention period
by oranger1426 Explorer in Getting Data In 04-18-2013
0 4
0
4
shahamit
I have installed Splunk 5.0.2 and a universal forwarder on one of the application servers to forward glassfish logs t...
by shahamit Explorer in Getting Data In 04-18-2013
0 2
0
2
I_am_Jeff
My security people have asked if there is a self-monitoring capability in Splunk to track situations such as A disgr...
by I_am_Jeff Communicator in Getting Data In 04-18-2013
1 3
1
3
aaronkorn
Can splunk read in mlg files or do you have to use a decode for it to be in plain text?
by aaronkorn Splunk Employee Splunk Employee in Getting Data In 04-18-2013
0 1
0
1
vincenty
I am trying to parse source path for a sub-directory name and its file name. My source files are as follows: source...
by vincenty Explorer in Getting Data In 04-18-2013
0 1
0
1
jgodfrey_kumc
Mt question here is very similar to the question posted here: http://serverfault.com/questions/469383/iis-advanced-l...
by jgodfrey_kumc Engager in Getting Data In 04-18-2013
0 4
0
4
splunkIT
If I need to monitor 2 different file types in the same folder and send them to different indexes, how do I do that?
by splunkIT Splunk Employee Splunk Employee in Getting Data In 04-18-2013
1 1
1
1
mcbradford
I am using the following to clean up output: rex mode=sed field=search_google2 "s/\%20/ /g";"s/\%5B/[/g" | rex mode=...
by mcbradford Contributor in Getting Data In 04-18-2013
0 1
0
1
deyeo
Everytime a email alert is sent, it contains a CSV file (as attachment) that only contains 101 rows even though the a...
by deyeo Path Finder in Getting Data In 04-17-2013
0 1
0
1
1234testtest
For java sdk, output mode as json, I am getting fields sent from splunk and their values as json. But how ever is the...
by 1234testtest Path Finder in Getting Data In 04-17-2013
0 3
0
3
msgtrk
以下のような日本語を含むタイムスタンプをSplunkに認識させるにはどのような設定が必要ですか? 金 3月 22 11:24:40 2013: Total time in the report period (60.000671...
by msgtrk Path Finder in Getting Data In 04-16-2013
0 3
0
3
lqiao
Hi, When I execute command splunk list monitor: I see that there are two different types of monitoring: Monitored di...
by lqiao Explorer in Getting Data In 04-16-2013
1 1
1
1
Splunk_U
I have made the UF as the deployment client. In the deployment server I have created an app that have the inputs.conf...
by Splunk_U Path Finder in Getting Data In 04-16-2013
0 2
0
2
TucoRameriz
Sorry in advance to the newbie question but, is there a way to import a list of IP addresses into splunk search query...
by TucoRameriz Explorer in Getting Data In 04-16-2013
1 3
1
3
virtualpony
Hi, I am trying to construct an input.conf stanza + whitelist/blacklist rule to look for the following: accept all *...
by virtualpony Path Finder in Getting Data In 04-16-2013
1 3
1
3
Parameter
Hi, I like the method of indexing files as they appear in the syslog-ng log directory where each host goes to a di...
by Parameter Explorer in Getting Data In 04-16-2013
1 5
1
5
Branden
I have a large number of Universal Forwarders that forward Apache access logs. On my systems, the apache access logs ...
by Branden Builder in Getting Data In 04-16-2013
0 2
0
2
LauraBre
Hello, I want to put several single in a same column so I add the attribut grouping in my xml file but I have a prob...
by LauraBre Communicator in Getting Data In 04-16-2013
0 1
0
1
ssankeneni
How can I verify if my universal forwarder is receiving the data on the UDP port ? I don't see any thing in my splunk...
by ssankeneni Communicator in Getting Data In 04-15-2013
0 3
0
3
diegosainz
I would like create a monitor/alert that looks for a *.msg file in a particular folder on the quarter hour. Any advi...
by diegosainz Path Finder in Getting Data In 04-15-2013
0 1
0
1
mhorn
is it possible to define the source and sourcetype fields to match a folder name? On each server our log structure ...
by mhorn New Member in Getting Data In 04-15-2013
0 12
0
12
ivantn21
Hello, Here at my company we have one search head and three indexers.... We have a standalone server that has an Hea...
by ivantn21 Explorer in Getting Data In 04-15-2013
1 5
1
5
vincenty
I am monitoring a series of directories. I want to blacklist any (sub)directories that is starting with a ".". i....
by vincenty Explorer in Getting Data In 04-15-2013
0 2
0
2
mirza94
Hello, I'm new to Splunk. On my server (Linux) I have splunk and a internal web site. Now I need to monitor the Wordp...
by mirza94 Engager in Getting Data In 04-15-2013
0 2
0
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...
Top Solution Authors