Getting Data In

Getting Data In
Community Activity
mehmettecer
Both of my servers are Linux OS and I am using latest Splunk 4.2. I can forward from UF to Splunk to index, but ever...
by mehmettecer Explorer in Getting Data In 03-14-2013
1 5
1
5
dengjin
./splunk add monitor col1 what's the col1?
by dengjin New Member in Getting Data In 03-13-2013
0 1
0
1
marcpatron
I am trying to index the local windows eventlogs, but there appears to be an issue reading the "Security" eventlog, a...
by marcpatron Explorer in Getting Data In 03-13-2013
0 4
0
4
mike7860
Hi all: I would like to know how do we delete logs from an indexer after 90 days in splunk. Some answers durected me...
by mike7860 Explorer in Getting Data In 03-13-2013
1 1
1
1
jared_anderson
I have active directory sending logs to my Splunk server via a Universal forwarder. I want to create alerts for when ...
by jared_anderson Path Finder in Getting Data In 03-13-2013
0 7
0
7
lpolo
I have this log event: 2013-02-01 17:23:46,877 query id=a0e22777-2aaf-4486-9a56-fd1dae24bb82{ "start" : 1, "retu...
by lpolo Motivator in Getting Data In 03-13-2013
0 4
0
4
cpetterborg
I have some searches that, when I list them in Manager, don't have anything but Run and Clone under Actions. There is...
by SplunkTrust SplunkTrust in Getting Data In 03-12-2013
0 3
0
3
donald_xero
We're trying to push event data from a heavy forwarder to our central indexer over a VPN with a fairly high RTT (~180...
by donald_xero Explorer in Getting Data In 03-12-2013
0 4
0
4
sloshburch
My universal fowarders are not hashing the sslPassword file stored at the etc/system location after restart. Instead...
by sloshburch Ultra Champion in Getting Data In 03-12-2013
0 3
0
3
tdrisdelle
Is there any way to use the CLI to configure the blacklist (in inputs.conf) file? The docs seem to indicate no... bu...
by tdrisdelle Engager in Getting Data In 03-12-2013
1 2
1
2
ephemeric
Hello all, Forgive my hasty question, it's late and my articulation has dwindled along with my brain capacity... We...
by ephemeric Contributor in Getting Data In 03-12-2013
0 11
0
11
vragosta
I have the following alert created in Splunk to alert me when the number of firewall drops exceeds 30 within a specif...
by vragosta Path Finder in Getting Data In 03-12-2013
0 2
0
2
ephemeric
Greetz, When a heavy forwarder is indexing and forwarding, does it keep track of what is indexed at what point and w...
by ephemeric Contributor in Getting Data In 03-12-2013
1 3
1
3
sunrise
Universal Forwarder(以下、UF)を利用してWindowsイベントログを収集する際、 current_onlyオプションによって以下の挙動になるかと思います。 <current_only=0の場合> UFはホスト内...
by sunrise Contributor in Getting Data In 03-12-2013
1 3
1
3
jbreu
I am having trouble getting the IIS logs and Message Tracking logs to show up Splunk. I am able getting some Exchange...
by jbreu Explorer in Getting Data In 03-12-2013
0 3
0
3
lzhang_soliton
Hi, I have been storing two types of log in the same directory. One is ANSI, another is Unicode. I use different def...
by lzhang_soliton Path Finder in Getting Data In 03-12-2013
0 2
0
2
Dark_Ichigo
Will this limit this forwarding speed to the Indexer? [thruput] maxKBps = <integer> * If specified and not z...
by Dark_Ichigo Builder in Getting Data In 03-11-2013
0 2
0
2
KNichol5hd
I am a new Splunk user who uses Splunk to find infected hosts on our network. I currently run 3 separate searches to ...
by KNichol5hd Explorer in Getting Data In 03-11-2013
0 2
0
2
ghannemann
Hi I have a forwarder pushing java log data to an indexer. The inputs on the index was set to log4j. However in th...
by ghannemann Engager in Getting Data In 03-11-2013
0 4
0
4
dondky
Hi guys, I'm stumped on task I've been working on for the last few weeks. We are extracting about 1.5 million lines ...
by dondky Path Finder in Getting Data In 03-11-2013
0 4
0
4
rexcze
Hello, I have this log: 07-Mar-2013 18:44:17.540 client 172.16.30.10#47729: query: www.atlas.cz IN A + (172.16.30.1...
by rexcze New Member in Getting Data In 03-11-2013
0 3
0
3
AaronMoorcroft
Hi Guys So I'm sending out logs to a 3rd party regarding one of our servers, the logs when they are received look li...
by AaronMoorcroft Communicator in Getting Data In 03-11-2013
0 1
0
1
Takajian
I am thinking to use data duplication function in clustering environment. I understand there are search factors and r...
by Takajian Builder in Getting Data In 03-10-2013
0 5
0
5
Adrian
Require assistance to formulate a search which identifies the same source IP(src) across one or more hosts (opposite ...
by Adrian Path Finder in Getting Data In 03-08-2013
0 3
0
3
marellasunil
How to moniter apache instance of a Unix server in splunk. There are 10 apache instances running every time in Unix s...
by marellasunil Communicator in Getting Data In 03-08-2013
0 1
0
1
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...