| Thread Info | |||||
|---|---|---|---|---|---|
| 
        We have two Linux servers using Splunk 5.0.1 on 64-bit. 
  A full Splunk install (SplunkD and SplunkWeb). We created ...
        
         
           by 
           
                
                    
                        atewari
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               11-29-2012
             
           
         
        | 
		
		0
   | 
	  
	  25
	 | |||
| 
        I want to group consecutive lines starting with the same pattern. I know the TRANSACTION command can be used as well,...
        
         
           by 
           
                
                    
                        Paolo_Prigione
                    
                
           
             
             
               Builder
             
           
           in
           Getting Data In
           
           
              
               07-12-2011
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        We are running Splunk 4.3.4.  
  Here is a sample stack trace from the server along with the results from a search fo...
        
         
           by 
           
                
                    
                        Ellen
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Getting Data In
           
           
              
               12-07-2012
             
           
         
        | 
		
		1
   | 
	  
	  1
	 | |||
| 
        Hi, 
  Have attempted to update to version 5 this morning and it's not doing anything... I've used truss to check all...
        
         
           by 
           
                
                    
                        jonesy1234
                    
                
           
             
             
               Engager
             
           
           in
           Getting Data In
           
           
              
               10-30-2012
             
           
         
        | 
		
		1
   | 
	  
	  2
	 | |||
| 
        is there anyyway to define at what point in time windows event logs will start being collected by Splunk UF? 
  We ha...
        
         
           by 
           
                
                    
                        r999
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               12-06-2012
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hi, Guys  
  Could you guys help me about -> give me some detailed manual? 
  1.AIX Detailed Setting Manual Docs. 2....
        
         
           by 
           
                
                    
                        qkwltk
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               12-06-2012
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        I would like to pause indexing when I reach 95% of my license. I have the Nagios check built, I just need the command...
        
         
           by 
           
                
                    
                        talbot7
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               12-05-2012
             
           
         
        | 
		
		0
   | 
	  
	  15
	 | |||
| 
        I'm working on a procedure to move from an old indexer to a new indexer without losing any events. The configuration ...
        
         
           by 
           
                
                    
                        bloom_dfarrell
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               12-06-2012
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I have configured this Windows Server 2008 software as indicated on this website: 
  https://www.fuzeqna.com/sonicwal...
        
         
           by 
           
                
                    
                        woodcock
                    
                
           
             
             
               Esteemed Legend
             
           
           in
           Getting Data In
           
           
              
               12-03-2012
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        Need to be able to pass host from a syslog message in a trap outbound from Splunk. of the nice configured varbinds, h...
        
         
           by 
           
                
                    
                        jonmcarr
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               04-19-2012
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I have the splunk forwarder installed on my Snort box and have it pointed to my indexer. It is sending data over, but...
        
         
           by 
           
                
                    
                        rmcdougal
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               12-05-2012
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hi, Good Day  Guys, I have a Question about Splunk Enviroment. 
   
  
   
     Unix OS AIX 6.1 Server in Vmware Env...
        
         
           by 
           
                
                    
                        qkwltk
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               12-05-2012
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hi, 
  When I am trying to export my Result in .csv it is coming garbled data for some of the fileds as those fields ...
        
         
           by 
           
                
                    
                        abhayneilam
                    
                
           
             
             
               Contributor
             
           
           in
           Getting Data In
           
           
              
               12-04-2012
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hi All,  
  Relatively new to Splunk, but am making good progress.  
  I have a unique situation. I have an ASA loggi...
        
         
           by 
           
                
                    
                        ahucker
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               12-04-2012
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I have defined input.conf under deployment server.  
  [monitor://D:\SystemX]
whitelist = \GenericService.log$
 
  I ...
        
         
           by 
           
                
                    
                        nikhilagrawal
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               06-06-2012
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I am trying to override the host field based on an element in the source path. This is data that is being forwarded f...
        
         
           by 
           
                
                    
                        wwwdrich
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               12-03-2012
             
           
         
        | 
		
		1
   | 
	  
	  4
	 | |||
| 
        We are in a bit of pickle currently trying to disassociate indexed data from a sourcetype that is currently tied to a...
        
         
           by 
           
                
                    
                        asarolkar
                    
                
           
             
             
               Builder
             
           
           in
           Getting Data In
           
           
              
               07-04-2012
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        After starting splunk stops immediately with 
  in splunkd.log 
   
   12-03-2012 16:16:26.414 -0800 ERROR IndexProce...
        
         
           by 
           
                
                    
                        yannK
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Getting Data In
           
           
              
               12-03-2012
             
           
         
        | 
		
		2
   | 
	  
	  4
	 | |||
| 
        We have two indexers and a single search head: Splunk1 Splunk2 Splunkweb 
  Both Splunk1 and Splunk2 have their own i...
        
         
           by 
           
                
                    
                        zindain24
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               12-04-2012
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hi, 
  I am trying to setup a heartbeat to know if our Splunk forwarders are working fine. From this forum, I found I...
        
         
           by 
           
                
                    
                        sdevadas
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               04-17-2012
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Hi all 
  i used the below code..to list down the sourcetype of the main indx in the dropdown .. 
   sources 
    
  ...
        
         
           by 
           
                
                    
                        splunkpoornima
                    
                
           
             
             
               Communicator
             
           
           in
           Getting Data In
           
           
              
               12-04-2012
             
           
         
        | 
		
		0
   | 
	  
	  7
	 | |||
| 
        Hey, 
  I have a 16-core windows 2003 server running Splunk v4.3.1 which is used for both searching and indexing. On ...
        
         
           by 
           
                
                    
                        Ant1D
                    
                
           
             
             
               Motivator
             
           
           in
           Getting Data In
           
           
              
               11-19-2012
             
           
         
        | 
		
		0
   | 
	  
	  8
	 | |||
| 
        I'm working with data that looks like this: 
   
   QA4 :: 1354371771 :: 020_grid_progress :: M020_grid_progress :: a...
        
         
           by 
           
                
                    
                        fandingo
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               12-03-2012
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        How can I delete the older UPDATE_TIME record(record2). 
  UNIQUE_ID, UPDATE_TIME・・・・・・ record1: 10001,2012/12/01,・・・...
        
         
           by 
           
                
                    
                        riku4809
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               12-03-2012
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Copying everything exactly how it appears... 
  I have this in my inputs.conf: 
  [monitor:///opt/firewalker/data/*/*...
        
         
           by 
           
                
                    
                        Ricapar
                    
                
           
             
             
               Communicator
             
           
           in
           Getting Data In
           
           
              
               11-21-2012
             
           
         
        | 
		
		0
   | 
	  
	  4
	 |