Getting Data In

Getting Data In
Community Activity
richnavis
It's not listed as being supported, but I wondered whether anyone has tried it with this version..
by richnavis Contributor in Getting Data In 04-09-2013
1 1
1
1
aaronkorn
Is there a way on the universal forwarder to send different data types to different indexers? For example, we want to...
by aaronkorn Splunk Employee Splunk Employee in Getting Data In 04-09-2013
0 3
0
3
chimbudp
I have installed Splunk forwarder on a Windows 2003 Server S2- 64-bit I have set the INPUTS.CONF,WMI.CONF to capture...
by chimbudp Contributor in Getting Data In 04-09-2013
0 1
0
1
SplunkFu
Hi there, I'm hoping this is a simple question... We have 50+ forwarders, and I'm trying to locate the forwarder th...
by SplunkFu Path Finder in Getting Data In 04-09-2013
0 2
0
2
shivanshuk
I have installed splunk on machine 1 and universal forwarder on machine 2. I can see on forwarder: C:\Program Files\...
by shivanshuk Explorer in Getting Data In 04-09-2013
0 1
0
1
oranger1426
Syslogs already has all the logs from other server using snare udp 514 Do I need to configure anything on the splunk...
by oranger1426 Explorer in Getting Data In 04-08-2013
0 3
0
3
aaronkorn
Hello, I have been trying to set an index retention policy on my indexer but it does not seem to be removing any of ...
by aaronkorn Splunk Employee Splunk Employee in Getting Data In 04-08-2013
0 1
0
1
nnachefski
How do you stream real-time results via the rest api? I've tried using the typical search submit method, which alway...
by nnachefski Engager in Getting Data In 04-08-2013
4 4
4
4
pepepito
Hi. I just setup a free account in splunkstorm and try to set up rsyslog base on the documentation and I didn't see ...
by pepepito New Member in Getting Data In 04-06-2013
0 1
0
1
a212830
Hi, I have a csv file with headers that needs processing. I want to 1) filter out the header and 2) have the fields ...
by a212830 Champion in Getting Data In 04-05-2013
0 2
0
2
craigrussell
How do I deal with large syslog files that keep growing? Do I just delete them or is there an automated way of rollin...
by craigrussell New Member in Getting Data In 04-05-2013
0 4
0
4
royimad
I have a log with multiple lines that contains several timestamps. When monitoring the logs splunk is split them into...
by royimad Builder in Getting Data In 04-05-2013
0 1
0
1
snehal8
Hello everyone, i read this following link this Now i have one question in my mind,what happen when more than 10 r...
by snehal8 Path Finder in Getting Data In 04-05-2013
1 2
1
2
abhayneilam
Hi, I have configured my props.conf and mentioned the "sourcetype" but later I dont see that sourcetype listed in th...
by abhayneilam Contributor in Getting Data In 04-05-2013
0 6
0
6
borisalves
I have a line that prints 2/20/13 6:45:45.000 PM [2013-02-20 18:45:45] FATAL so that is ok, but what i really wa...
by borisalves Path Finder in Getting Data In 04-05-2013
0 8
0
8
mikelanghorst
After setting a rather simple props entry for sourcetype [sharepoint] for our log to break events only after datestam...
by mikelanghorst Motivator in Getting Data In 04-04-2013
1 1
1
1
twkan
Hello all, I have a series of logs that looks like this: 200312,111523 -> this means 20 March 2012, 11:15:23 am 20...
by twkan Splunk Employee Splunk Employee in Getting Data In 04-04-2013
0 1
0
1
the_wolverine
and its not working. Why? I can tell by viewing the event in Splunk that my WMI events have the following metadata:...
by the_wolverine Champion in Getting Data In 04-04-2013
1 5
1
5
lpolo
The following URI returns the metadata information related to a saved search named "test" found in application "searc...
by lpolo Motivator in Getting Data In 04-04-2013
0 5
0
5
soimeng
my transform.conf [setnull] REGEX = . DEST_KEY = queue FORMAT = nullQueue [setparsing] REGEX =(?msi)^EventCode=4663...
by soimeng Explorer in Getting Data In 04-04-2013
0 3
0
3
dart
If I have a SEDCMD that is removing data, can I get the length of data removed, eg: ### RAW EVENT 12:01:01 Recieved ...
by dart Splunk Employee Splunk Employee in Getting Data In 04-04-2013
2 1
2
1
rechteklebe
Hi, i would like to use one of my universal forwarder as a second indexer. Please help me how to do it. In the seco...
by rechteklebe Path Finder in Getting Data In 04-04-2013
0 1
0
1
nooo
Hello, We're planning on forwarding our ASA logs to Splunk for log correlation etc, but do not want every event to b...
by nooo New Member in Getting Data In 04-03-2013
0 1
0
1
mcculloh
Trying to start a local install of the free splunk server on a red hat machine running linux 2.6.32. I am getting err...
by mcculloh New Member in Getting Data In 04-03-2013
0 3
0
3
j666gak
Hi, I'm having a bit of a headache. I am trying to index an XML file however I want the event date to be the date th...
by j666gak Communicator in Getting Data In 04-03-2013
0 4
0
4
Get Updates on the Splunk Community!

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...
Top Solution Authors