| Hi, Can I use the following expression in my inputs.conf /data/logs/kim/.../**MS?.log.gz* Or /data/logs/kim/.../*... by mkelderm Path Finder in Getting Data In 07-09-2012 1 1 | 1 | 1 | ||
| Hi, We have spec:d volumes for use in out indexes.conf and we are also (trying) to limit this volumes content with t... by lmyrefelt Builder in Getting Data In 07-09-2012 1 4 | 1 | 4 | ||
| Hi. We are trying to monitor one custom file in a non-syslogging service on a linux Ubuntu 11.04 64 bit server. For... by certivox New Member in Getting Data In 07-08-2012 0 1 | 0 | 1 | ||
| Hello, I am setting up a test lab with Splunk. As I have a VPS (Virtual Private Server) for web hosting I thought it... by j666gak Communicator in Getting Data In 07-07-2012 0 1 | 0 | 1 | ||
| I have multiple data inputs going into one index. Is there a way to delete only one of those data inputs and scrub i... by sthao New Member in Getting Data In 07-06-2012 0 3 | 0 | 3 | ||
| Hi all, I have a question about script alert. Now the script alert will transform the result to gzip filetype. Is th... by Anthony_Hou Path Finder in Getting Data In 07-05-2012 2 2 | 2 | 2 | ||
| I have a log which contains entries like the following: (3/07/12 13:13:09) 8856: < RingBufferModule::initialize() (3... by sajbutler Path Finder in Getting Data In 07-05-2012 0 4 | 0 | 4 | ||
| We started to lose accessing Splunkweb running on Windows 2k8 Server. When we checked status of the service. We've no... by Masa Splunk Employee 3 4 | 3 | 4 | ||
| Is there a way to remove the Header column row after performing the outputcsv command during a Splunk search? by efelder0 Communicator in Getting Data In 07-05-2012 2 3 | 2 | 3 | ||
| Reading a temperature sensor (DS18B20) from out side. Every so often I get a bad data set. Jul 2 23:26:40 malakoff ... by talbot7 Path Finder in Getting Data In 07-05-2012 0 6 | 0 | 6 | ||
| Hi Splunkies, another question by me... I run a script every 15 min which counts DFS connections on different server... by jan_wohlers Path Finder in Getting Data In 07-05-2012 0 1 | 0 | 1 | ||
| If multiple hosts, in different time zones, are sending logs to Splunk . In that case how to configure Timezone props... by ranjyotiprakash Communicator in Getting Data In 07-05-2012 1 6 | 1 | 6 | ||
| In my search result I want to exclude some result that belongs to eventtype, Is it possible ? my search is source... by jangid Builder in Getting Data In 07-05-2012 3 3 | 3 | 3 | ||
| I'm consuming a qa test log that has a fairly erratic format, but I was able to identify a line breaker regex to grou... by heathm Explorer in Getting Data In 07-04-2012 2 5 | 2 | 5 | ||
| Hello, I'm trialling Splunk purely as a syslog server, and have installed it on a windows 2003 server, and can recie... by GLC2012 Explorer in Getting Data In 07-04-2012 1 7 | 1 | 7 | ||
| When applying compression on forwarder to indexer, I am suspecting it's more efficient due to splunk comsuming less N... by clyde772 Communicator in Getting Data In 07-04-2012 0 1 | 0 | 1 | ||
| after few investigations on my own , I have a more specific question. what is the correct way to configure props.con... by avishayh Explorer in Getting Data In 07-04-2012 0 2 | 0 | 2 | ||
| Example of actual inputs.conf [monitor:////data/example/server/example/log/*.log] sourcetype=jboss index=idx_sep_dev... by unix New Member in Getting Data In 07-03-2012 0 4 | 0 | 4 | ||
| Has anybody experienced condition where Forwarder is not reading and sending old logs fast? Eventhough there's plent... by clyde772 Communicator in Getting Data In 07-03-2012 0 2 | 0 | 2 | ||
| How do you build a search to total the bytes transfered (sending and recieving) by ip address for the last 24 hours, ... by rpetrini Engager in Getting Data In 07-03-2012 0 3 | 0 | 3 | ||
| Hey Splunkers! I always thought or heard that data that gets input to forwarder gets "cooked" meaning compressed b... by clyde772 Communicator in Getting Data In 07-03-2012 0 1 | 0 | 1 | ||
| Hi, I already checked the API Endpoint list if my request is covered. But cannot find it. I'd like to change the da... by nebel Communicator in Getting Data In 07-03-2012 0 2 | 0 | 2 | ||
| Hi, I am just looking at a new data input in Splunk. In some cases I am seeing one timestamp per event which is what... by Ant1D Motivator in Getting Data In 07-02-2012 0 3 | 0 | 3 | ||
| I had a simple report showing the past 7 day's (by day) not per hour using the timechart span="86400s" function. Th... by lancealotx Explorer in Getting Data In 07-02-2012 0 2 | 0 | 2 | ||
| I've been having trouble getting a host override transformation in my props.conf/transforms.conf to work and want to ... by dpadams Communicator in Getting Data In 07-02-2012 0 7 | 0 | 7 |