| We have a very large environment.. and with Splunk charging by the GB/day, we obviously have an interest in controlli... by Ricapar Communicator in Getting Data In 11-07-2012 0 4 | 0 | 4 | ||
| One of my sources coming from a universal forwarder needs to have have it's truncate option set to 0. I have edited ... by bread555 Explorer in Getting Data In 11-07-2012 1 2 | 1 | 2 | ||
| Hi, I am new to splunk and when i add datainputs i was not known about the timestamp issue and later i explored it. w... by sruthy Explorer in Getting Data In 11-07-2012 1 1 | 1 | 1 | ||
| I have configured approx. 100 access points to send syslog events to both Splunk and to a kiwi syslog server I have s... by pdherndon New Member in Getting Data In 11-06-2012 0 8 | 0 | 8 | ||
| I've heard that Splunk recommends monitoring of rolled log files (eg. file.log.1, file.log.2, etc) under certain sit... by the_wolverine Champion in Getting Data In 11-06-2012 0 3 | 0 | 3 | ||
| Hey Guys, Im trying to come up with some searches for our HR department. We sometimes have to present them with evide... by mrgibbon Contributor in Getting Data In 11-06-2012 0 5 | 0 | 5 | ||
| Hello, i would like to add a monitor for EventLog:Security. This EventLog contains many entries, and if i add it dir... by n_greder New Member in Getting Data In 11-06-2012 0 3 | 0 | 3 | ||
| Hello, I search a way to get realtime logs from DMZ-Zone into a Trusted Network, where the Indexer is located. A Fo... by tjensen Explorer in Getting Data In 11-06-2012 0 4 | 0 | 4 | ||
| instead of storing the cisco firewall logs into "summary" index. i would like to store in a index called "firewall". ... by deyeo Path Finder in Getting Data In 11-05-2012 0 1 | 0 | 1 | ||
| Hello there, I have currently deployed Splunk in our network using SplunkLightForwarders and one central indexing se... by CerielTjuh Path Finder in Getting Data In 11-05-2012 1 14 | 1 | 14 | ||
| Hi Everyone, I have windows security event filter setup and working on my indexer. However I want to filter on three... by barne_dn Explorer in Getting Data In 11-05-2012 0 3 | 0 | 3 | ||
| Hi, I have a file which contains the below content: abhay|vikram|singh|26|kolkata murari|kumar|singh|28|mumbai I wa... by abhayneilam Contributor in Getting Data In 11-05-2012 0 9 | 0 | 9 | ||
| I am forwarding data from indexer to heavy forwarder How I can append host name in event (_raw) in indxer that will ... by kml_uvce Builder in Getting Data In 11-05-2012 0 4 | 0 | 4 | ||
| Hi, I have JSON data being indexed from a syslog file i.e Nov 2 23:04:47 host1 /usr/local/bin/audit.rb[24503]: { "... by matthewparry Path Finder in Getting Data In 11-04-2012 0 1 | 0 | 1 | ||
| Hi, I have a data as : abhay|vikram|singh|26|kolkata murari|kumar|singh|28|mumbai and in my transfoms.conf I hav... by abhayneilam Contributor in Getting Data In 11-04-2012 0 1 | 0 | 1 | ||
| Good Day, I first tried to use the Cisco Security Suite in anticipation of getting more Cisco devices but realized t... by inerdgrl New Member in Getting Data In 11-04-2012 0 1 | 0 | 1 | ||
| Hi All I want to set my Splunk server to keep logs active for 30 days then compress those logs, save it in another d... by opel121 New Member in Getting Data In 11-04-2012 0 1 | 0 | 1 | ||
| Hi, I've been looking at the documentation i.e http://docs.splunk.com/Documentation/Splunk/4.3.2/Developer/ScriptedI... by matthewparry Path Finder in Getting Data In 11-02-2012 0 11 | 0 | 11 | ||
| It seems like our indexers do not properly get distributed load in our cluster according to our volume report alerts,... by sonicZ Contributor in Getting Data In 11-02-2012 0 3 | 0 | 3 | ||
| Hello Splunkers - I'm having trouble figuring out how to make the following work. I get usage files from a popular ... by stensonb Engager in Getting Data In 11-02-2012 2 2 | 2 | 2 | ||
| The documentation says Splunk is creating a CRC hash of the first and last 256 bytes of a file in order to detect wea... by ziegfried Influencer in Getting Data In 11-02-2012 5 3 | 5 | 3 | ||
| Hi. We are seeing duplicate logfile entries in our Search results with certain logfiles. It is happening in a direc... by mfeeny1 Path Finder in Getting Data In 11-02-2012 0 2 | 0 | 2 | ||
| I created some incorrect logs with the command sourcetype="DS Logs" | delete I have can_delete permission, and the... by lain179 Communicator in Getting Data In 11-02-2012 0 3 | 0 | 3 | ||
| I would like to generate a report that'll list all the indexes and indexed volume usage for all the servers in my env... by mike7860 Explorer in Getting Data In 11-02-2012 0 1 | 0 | 1 | ||
| hi guys - i have a stand-alone splunk server that i'm trying to size appropriately. we have a fixed 3TB volume to ... by awurster Contributor in Getting Data In 11-02-2012 0 6 | 0 | 6 |