Thread Info | |||||
---|---|---|---|---|---|
Hi, is anyone out there having a Slow search and missed alerts on Search head. we have installed search head on 64 bi...
by
aandrew
New Member
in
Getting Data In
11-06-2012
|
0
|
9
| |||
We have a very large environment.. and with Splunk charging by the GB/day, we obviously have an interest in controlli...
by
Ricapar
Communicator
in
Getting Data In
10-19-2012
|
0
|
4
| |||
One of my sources coming from a universal forwarder needs to have have it's truncate option set to 0. I have edited t...
by
bread555
Explorer
in
Getting Data In
11-06-2012
|
1
|
2
| |||
Hi, I am new to splunk and when i add datainputs i was not known about the timestamp issue and later i explored it. w...
by
sruthy
Explorer
in
Getting Data In
11-07-2012
|
1
|
1
| |||
I have configured approx. 100 access points to send syslog events to both Splunk and to a kiwi syslog server I have s...
by
pdherndon
New Member
in
Getting Data In
11-05-2012
|
0
|
8
| |||
I've heard that Splunk recommends monitoring of rolled log files (eg. file.log.1, file.log.2, etc) under certain situ...
by
the_wolverine
Champion
in
Getting Data In
11-05-2012
|
0
|
3
| |||
Hey Guys, Im trying to come up with some searches for our HR department. We sometimes have to present them with evide...
by
mrgibbon
Contributor
in
Getting Data In
11-05-2012
|
0
|
5
| |||
Hello,
i would like to add a monitor for EventLog:Security. This EventLog contains many entries, and if i add it d...
by
n_greder
New Member
in
Getting Data In
11-05-2012
|
0
|
3
| |||
Hello, I search a way to get realtime logs from DMZ-Zone into a Trusted Network, where the Indexer is located. A Fo...
by
tjensen
Explorer
in
Getting Data In
11-05-2012
|
0
|
4
| |||
instead of storing the cisco firewall logs into "summary" index. i would like to store in a index called "firewall". ...
by
deyeo
Path Finder
in
Getting Data In
11-05-2012
|
0
|
1
| |||
Hello there,
I have currently deployed Splunk in our network using SplunkLightForwarders and one central indexing ...
by
CerielTjuh
Path Finder
in
Getting Data In
04-16-2010
|
1
|
14
| |||
Hi Everyone,
I have windows security event filter setup and working on my indexer. However I want to filter on thr...
by
barne_dn
Explorer
in
Getting Data In
10-10-2012
|
0
|
3
| |||
Hi, I have a file which contains the below content:
abhay|vikram|singh|26|kolkata murari|kumar|singh|28|mumbai
...
by
abhayneilam
Contributor
in
Getting Data In
11-04-2012
|
0
|
9
| |||
I am forwarding data from indexer to heavy forwarder How I can append host name in event (_raw) in indxer that will b...
by
kml_uvce
Builder
in
Getting Data In
10-30-2012
|
0
|
4
| |||
Hi,
I have JSON data being indexed from a syslog file i.e
Nov 2 23:04:47 host1 /usr/local/bin/audit.rb[24503]:...
by
matthewparry
Path Finder
in
Getting Data In
11-02-2012
|
0
|
1
| |||
Hi,
I have a data as :
abhay|vikram|singh|26|kolkata murari|kumar|singh|28|mumbai
and in my transfoms.conf ...
by
abhayneilam
Contributor
in
Getting Data In
11-04-2012
|
0
|
1
| |||
Good Day, I first tried to use the Cisco Security Suite in anticipation of getting more Cisco devices but realized t...
by
inerdgrl
New Member
in
Getting Data In
10-18-2011
|
0
|
1
| |||
Hi All
I want to set my Splunk server to keep logs active for 30 days then compress those logs, save it in another...
by
opel121
New Member
in
Getting Data In
11-04-2012
|
0
|
1
| |||
Hi,
I've been looking at the documentation i.e http://docs.splunk.com/Documentation/Splunk/4.3.2/Developer/Scripte...
by
matthewparry
Path Finder
in
Getting Data In
10-31-2012
|
0
|
11
| |||
It seems like our indexers do not properly get distributed load in our cluster according to our volume report alerts,...
by
sonicZ
Contributor
in
Getting Data In
10-29-2012
|
0
|
3
| |||
Hello Splunkers -
I'm having trouble figuring out how to make the following work.
I get usage files from a popu...
by
stensonb
Engager
in
Getting Data In
04-27-2012
|
2
|
2
| |||
The documentation says Splunk is creating a CRC hash of the first and last 256 bytes of a file in order to detect wea...
by
ziegfried
Influencer
in
Getting Data In
07-13-2010
|
5
|
3
| |||
Hi. We are seeing duplicate logfile entries in our Search results with certain logfiles. It is happening in a directo...
by
mfeeny1
Path Finder
in
Getting Data In
01-13-2012
|
0
|
2
| |||
I created some incorrect logs with the command
sourcetype="DS Logs" | delete
I have can_delete permission, and...
by
lain179
Communicator
in
Getting Data In
11-01-2012
|
0
|
3
| |||
I would like to generate a report that'll list all the indexes and indexed volume usage for all the servers in my env...
by
mike7860
Explorer
in
Getting Data In
11-02-2012
|
0
|
1
|