Thread Info | |||||
---|---|---|---|---|---|
Does anyone know how we can use the timestamp of the file from the operating system as the timestamp for events? For ...
by
ngcgoon
Explorer
in
Getting Data In
03-07-2011
|
0
|
4
| |||
We're trying to forward data to a syslog server from a splunk server. However, seems that the hostname and process id...
by
acalvo
Explorer
in
Getting Data In
10-29-2010
|
2
|
6
| |||
I have a Splunk indexer (splunk-4.0.9-74233-linux-2.6-x86_64.rpm) sending cooked data to a Splunk forwarder (active_g...
by
nisse
Explorer
in
Getting Data In
08-02-2011
|
2
|
5
| |||
[1] May I know what are the differences between using monitor or fschange?
[2] Is there a documentation about fsch...
by
Nicholas_Key
Splunk Employee
in
Getting Data In
04-29-2010
|
2
|
2
| |||
I've seen a number of posts about this with varied responses.
Here's what I'm trying to do:
We have some web a...
by
Branden
Builder
in
Getting Data In
01-24-2012
|
0
|
7
| |||
Hi,
We have a cron job which periodically updates the lookup file. The file name is of the format lookup_mmddyyyy....
by
sscandoit
Explorer
in
Getting Data In
08-15-2011
|
1
|
2
| |||
I am new to splunk and am trying to set up a monitored directory. It appears that when browsing for an existing direc...
by
dzilk
Engager
in
Getting Data In
01-24-2012
|
1
|
2
| |||
We are converting from a single Splunk instantance to a cluster. At this time we are also implementing Universal Forw...
by
fk319
Builder
in
Getting Data In
01-25-2012
|
0
|
5
| |||
Hi,
I've tried everything. I have read all the answers and docs. A cannot force splunk indexer to forward all even...
by
awalesa
New Member
in
Getting Data In
01-24-2012
|
0
|
12
| |||
Hi Splunkers,
I am very new to Splunk and would like to monitor Windows servers, how do I configure the Windows bo...
by
tomero2011
Engager
in
Getting Data In
01-24-2012
|
0
|
1
| |||
I indexed a huge log with data that is going back to 2006. However when I try to search on this data it doesn't show ...
by
gnovak
Builder
in
Getting Data In
01-19-2012
|
0
|
12
| |||
Hi Splunk Gurus
We have problem with Splunk on Windows. Windows sends way to many events and logs to splunk indexe...
by
nitinthakur
New Member
in
Getting Data In
01-24-2012
|
0
|
3
| |||
Hello,
I have been try to configure the windows app to display data from additional hosts, but without success.
...
by
davidfreer
New Member
in
Getting Data In
11-21-2011
|
0
|
1
| |||
I have a UF sending logs to my indexer. The UF receives logs, via syslog, from several other systems. All my UFs, ind...
by
I_am_Jeff
Communicator
in
Getting Data In
01-13-2012
|
0
|
3
| |||
We have some Cisco devices that are sending syslog via port 514 natively (no splunk forwarder installed, obviously). ...
by
aferone
Builder
in
Getting Data In
01-18-2012
|
2
|
21
| |||
I'm testing Splunk with the following configuration: Splunk 4.3 indexer and Splunk Universal Forwarder 4.3 on a separ...
by
scaldwell1
New Member
in
Getting Data In
01-18-2012
|
0
|
1
| |||
I am performing the following test in my env,
props.conf [newcsvtest] REPORT-newcsvtest = newcsvtest SHOULD_LINEME...
by
schava2
Explorer
in
Getting Data In
01-22-2012
|
0
|
1
| |||
Dear Colleagues,
I am configuring Splunk to listen my File Server in the WMI Security Events. Splunk is listening ...
by
mgaleti
New Member
in
Getting Data In
12-05-2011
|
0
|
1
| |||
I was running a cold to frozen script that moved the forzen files into a separate directory per index.
/opt/splun...
by
imacdonald2
Path Finder
in
Getting Data In
01-20-2012
|
0
|
1
| |||
I have noticed that universal forwarders receiving data from a high-traffic input will fail to distribute events even...
by
hexx
Splunk Employee
in
Getting Data In
11-30-2011
|
3
|
2
| |||
I asked my Firewall admin to change the port for syslog to the Splunk indexer.
He changed it from 514 to 1514.
...
by
hartfoml
Motivator
in
Getting Data In
01-18-2012
|
0
|
2
| |||
My props and transforms.conf work fine and I am able to see the fields on the GUI of search heads ( We are running sp...
by
desi-indian
Path Finder
in
Getting Data In
01-09-2012
|
0
|
4
| |||
Situation:
I log into to splunk and find that data is not present when it should be. I log into the client machine...
by
jgauthier
Contributor
in
Getting Data In
10-28-2011
|
0
|
9
| |||
I've already got my single indexer spec'd to handle under 100Gigs a day and it meets the requirements. However i am g...
by
Chris_R_
Splunk Employee
in
Getting Data In
05-19-2010
|
2
|
3
| |||
What are some of the methods that I can remove the header row after running the 'outputcsv' command in my search?
...
by
efelder0
Communicator
in
Getting Data In
01-19-2012
|
1
|
2
|