| Hi, How would I parse a file that has two linebreaking formats? The first is when the line begins and ends with ast... by a212830 Champion in Getting Data In 03-17-2013 0 3 | 0 | 3 | ||
| I need to build a dashboard to parse the json data and show it more like Tree Structure.What is the best way, I can b... by Sriram Communicator in Getting Data In 03-15-2013 1 1 | 1 | 1 | ||
| Hi, How would I tell splunk to monitor a specific file through a set of subdirectories? Would I set a wildcard in th... by a212830 Champion in Getting Data In 03-15-2013 0 1 | 0 | 1 | ||
| We have several customers with Splunk. Is it possible to integrate more than 1 Splunk instance i ServiceNow? by arntm New Member in Getting Data In 03-15-2013 0 2 | 0 | 2 | ||
| The Exchange Server application we use, up until last weekend, was reporting data that appears to be an accurate refl... by jeffmartintx New Member in Getting Data In 03-15-2013 0 1 | 0 | 1 | ||
| We have a universal forwarder on linux that seems to get 'stuck' reading one of the two high event log files being re... by twstanley New Member in Getting Data In 03-15-2013 0 3 | 0 | 3 | ||
| Unable to start splunk forwarder service, below error returns. checking mgmt port [8089]: already bound ERROR: The m... by catch_mili Explorer in Getting Data In 03-15-2013 0 6 | 0 | 6 | ||
| I've got an event log from a sql server that I'm trying to import. When I view the file in a text editor, everything... by madmoravian New Member in Getting Data In 03-14-2013 0 1 | 0 | 1 | ||
| Hi all, I have an XML log file that looks something like this. <matrix> <datasource> <name>ABC</name> <... by wlsplunker New Member in Getting Data In 03-14-2013 0 3 | 0 | 3 | ||
| Hi Everybody, I am getting the following error message while trying to save remote performance counters for MSMQ ser... by danurag Explorer in Getting Data In 03-14-2013 0 3 | 0 | 3 | ||
| Should a props.conf even exist on universal forwarders? Is all that work (including timestamp and line-breaking) done... by a212830 Champion in Getting Data In 03-14-2013 0 2 | 0 | 2 | ||
| I've been trying to do a search time field extraction, using the EXTRACT- stanza in props.conf. From the props.con... by Adam_Sealey Explorer in Getting Data In 03-14-2013 0 2 | 0 | 2 | ||
| i added my Adium chat logs to be monitored by splunk. i see multiple repeats for any given log event. i verified the ... by monzy Communicator in Getting Data In 03-14-2013 1 6 | 1 | 6 | ||
| Hi all, I am working on putting my deployment server code in an external location, like GitHub. This part is working... by dcparker Path Finder in Getting Data In 03-14-2013 0 2 | 0 | 2 | ||
| I use the following commands on my light forwarders to add an index and set new files to use it. /opt/splunkforwa... by ddholstadz Explorer in Getting Data In 03-14-2013 0 2 | 0 | 2 | ||
| Both of my servers are Linux OS and I am using latest Splunk 4.2. I can forward from UF to Splunk to index, but ever... by mehmettecer Explorer in Getting Data In 03-14-2013 1 5 | 1 | 5 | ||
| 0 | 1 | |||
| I am trying to index the local windows eventlogs, but there appears to be an issue reading the "Security" eventlog, a... by marcpatron Explorer in Getting Data In 03-13-2013 0 4 | 0 | 4 | ||
| Hi all: I would like to know how do we delete logs from an indexer after 90 days in splunk. Some answers durected me... by mike7860 Explorer in Getting Data In 03-13-2013 1 1 | 1 | 1 | ||
| I have active directory sending logs to my Splunk server via a Universal forwarder. I want to create alerts for when ... by jared_anderson Path Finder in Getting Data In 03-13-2013 0 7 | 0 | 7 | ||
| I have this log event: 2013-02-01 17:23:46,877 query id=a0e22777-2aaf-4486-9a56-fd1dae24bb82{ "start" : 1, "retu... by lpolo Motivator in Getting Data In 03-13-2013 0 4 | 0 | 4 | ||
| I have some searches that, when I list them in Manager, don't have anything but Run and Clone under Actions. There is... by cpetterborg SplunkTrust 0 3 | 0 | 3 | ||
| We're trying to push event data from a heavy forwarder to our central indexer over a VPN with a fairly high RTT (~180... by donald_xero Explorer in Getting Data In 03-12-2013 0 4 | 0 | 4 | ||
| My universal fowarders are not hashing the sslPassword file stored at the etc/system location after restart. Instead... by sloshburch Ultra Champion in Getting Data In 03-12-2013 0 3 | 0 | 3 | ||
| Is there any way to use the CLI to configure the blacklist (in inputs.conf) file? The docs seem to indicate no... bu... by tdrisdelle Engager in Getting Data In 03-12-2013 1 2 | 1 | 2 |