Thread Info | |||||
---|---|---|---|---|---|
I have seen manytime where Splunk didn't copped either multi or single line data correctly ending up with events that...
by
clyde772
Communicator
in
Getting Data In
05-01-2010
|
0
|
1
| |||
I have an ISA web log of the following format. Splunk doesn't correctly identify the timestamp in every event, even t...
by
Ron_Naken
Splunk Employee
in
Getting Data In
04-30-2010
|
4
|
2
| |||
I am trying to implement file integrity monitoring. I have configured fschange as follows:
[fschange:/opt/bea/10_s...
by
jbidinger
Explorer
in
Getting Data In
04-28-2010
|
0
|
6
| |||
I see the same host in my Summary page in Search app with same event count.
They are the same host but show up lik...
by
micropotato
Engager
in
Getting Data In
04-30-2010
|
1
|
1
| |||
Hi everybody
At the moment I've got about 170 indexes on my indexer. I
What's the best practice limit of number...
by
Simon
Contributor
in
Getting Data In
04-28-2010
|
0
|
2
| |||
Can someone shed light on the purpose of the _s _st and _h indexed fields? These seem to correspond to source, source...
by
Lowell
Super Champion
in
Getting Data In
03-24-2010
|
0
|
2
| |||
What is the strptime-style %-variable that TIME_FORMAT would use for subseconds? The docs for props.conf suggest the ...
by
dwaddle
SplunkTrust
in
Getting Data In
04-28-2010
|
4
|
2
| |||
Regarding agent vs agentless data / event gatering, WMI (agentless) seems easier to setup from within Splunk to pull ...
by
maverick
Splunk Employee
in
Getting Data In
04-28-2010
|
1
|
2
| |||
My indexer has a Intel Xeon X5570 which has four cores.
http://ark.intel.com/Product.aspx?id=37111
How can I ma...
by
muebel
SplunkTrust
in
Getting Data In
04-27-2010
|
1
|
1
| |||
How can I tell which servers in my enterprise are forwarding to the master server. We do automated installs of vm's a...
by
bc_unixadm
Explorer
in
Getting Data In
04-27-2010
|
1
|
5
| |||
Can Splunk index events from my Checkpoint firewall logs? If so, how can I set that up?
by
maverick
Splunk Employee
in
Getting Data In
03-30-2010
|
1
|
4
| |||
Currently, all agents installed on hosts default to 'changeme' and this credential is still used when the forwarder i...
by
jradkowskiAAMC
Explorer
in
Getting Data In
04-26-2010
|
0
|
2
| |||
I had configured splunk forwarder and receiver in a Linux system as per the Admin manual. I tried searching the forwa...
by
sivakumar_inbox
Engager
in
Getting Data In
04-22-2010
|
1
|
2
| |||
We are on 4.05 and are using the default of memPoolMB = auto in indexes.conf. Is there a way I can find out what size...
by
cpenkert
Path Finder
in
Getting Data In
04-22-2010
|
1
|
5
| |||
Referenced Doc: http://www.splunk.com/base/Documentation/4.1/Admin/Moreaboutforwarders
I need to be able to send d...
by
SK110176
Path Finder
in
Getting Data In
04-19-2010
|
1
|
4
| |||
I've verified that the indexer (receiver) is the same or later version of Splunk as the forwarder. What log or config...
by
Jaci
Splunk Employee
in
Getting Data In
02-19-2010
|
4
|
6
| |||
We have on four Linux SLES10_64 Servers Splunk 3.4.4. Forwarders installed. Usually our production logs produce a con...
by
tpaulsen
Contributor
in
Getting Data In
04-23-2010
|
0
|
1
| |||
I have one splunk forwarder I need to segregate from other indexes. I have created its own index and I need to know h...
by
Alan_Bradley
Path Finder
in
Getting Data In
04-22-2010
|
1
|
2
| |||
Currently, when I try to run a search in Splunk, I get the following error message:
"Error in 'UnifiedSearch': Yo...
by
mctester
Communicator
in
Getting Data In
04-22-2010
|
1
|
1
| |||
Hello,
i want to collect logs from one forwarder (Splunk 4.0.10) and forward the data to different indexes on one ...
by
tpaulsen
Contributor
in
Getting Data In
04-13-2010
|
1
|
7
|