Getting Data In

Getting Data In
Community Activity
I-Man
We are a 90% Windows environment. Since we upgraded to 4.3.1, the WMI log format has changed ever so slightly. While ...
by I-Man Communicator in Getting Data In 04-13-2012
0 1
0
1
jeff
I have the following stansas deployed to lightweight forwarders running Windows: props.conf [WinEventLog:Security] ...
by jeff Contributor in Getting Data In 04-13-2012
0 6
0
6
sahil_singh
Hi, How can one get the host and source IP addresses in the event logs instead of hostname in either places. It is c...
by sahil_singh Explorer in Getting Data In 04-13-2012
0 7
0
7
echalex
Hi, Is there any way of creating indexes on several indexers centrally? For a fairly small indexer-farm, it isn't mu...
by echalex Builder in Getting Data In 04-12-2012
0 2
0
2
khyoung7410
hi universalforwarder receives and send the syslog data to do? If possible, how do?
by khyoung7410 Communicator in Getting Data In 04-12-2012
0 2
0
2
Brian_Osburn
I have a request from a user who wants to get some stats from the Exchange App around specific users. Namely they're...
by Brian_Osburn Builder in Getting Data In 04-12-2012
3 2
3
2
jbirchall1
Is it possible to set up forwarders to index data on the path of the file and a portion of the file name automaticall...
by jbirchall1 New Member in Getting Data In 04-12-2012
0 2
0
2
eugenekogan
As far as I can tell, setting maxVolumeDataSizeMB does not trigger bucket moves and has no impact at all. Does anyone...
by eugenekogan Explorer in Getting Data In 04-12-2012
0 6
0
6
tchristian
When I try to install any app from the zipped file, I get an error like: There was an error processing the upload. L...
by tchristian New Member in Getting Data In 04-12-2012
0 3
0
3
Glenn
Hi, I am using a props/transforms TRANSFORM to add the source (log file) name to the _raw log event line. props.con...
by Glenn Builder in Getting Data In 04-12-2012
0 1
0
1
kenchisho
Hi guys, I have installed Splunk 4.3 on a MAC OSX 10.7. I am trying to index data with non utf encoding. I have tri...
by kenchisho Path Finder in Getting Data In 04-12-2012
0 3
0
3
echalex
Hi, I'm having a weird problem with recognizing timestamps. The actual timestamp looks like this: [2012-04-11 11:24:...
by echalex Builder in Getting Data In 04-12-2012
0 4
0
4
wbfoxii
I have a Universal Forwarder looking at a directory holding our proxy logs. New logs are dumped into the directory e...
by wbfoxii Communicator in Getting Data In 04-12-2012
1 3
1
3
sarah89
please I need help , I deployed a universal forward by following tutorial "distributed deployement manual" The un...
by sarah89 Path Finder in Getting Data In 04-12-2012
1 16
1
16
JPValadas
Hi again, I got one question in filtering and routing to indexer. i got my props like this: pros.conf [WinEven...
by JPValadas Explorer in Getting Data In 04-12-2012
0 9
0
9
sconnors
In our environment (mid-size enterprise with remote sites) we have our primary indexer on dedicated hardware. All dat...
by sconnors Engager in Getting Data In 04-12-2012
0 5
0
5
johnamcafee
We need to index content that may contain in-line gzip (or other compression) content. We do not need to search on th...
by johnamcafee New Member in Getting Data In 04-11-2012
0 1
0
1
Mick
I wanted to see how Splunk would index my data, so I configured it to index a few files into a 'test' index. Now tha...
by Mick Splunk Employee Splunk Employee in Getting Data In 04-11-2012
3 6
3
6
Jason
I'm looking at a Splunk instance right now that is getting 99+% of its data as one particular sourcetype, from two he...
by Jason Motivator in Getting Data In 04-11-2012
1 5
1
5
mataharry
Hi I have a license pool for X Gb per day, and I blow it every almost every single day. How to selectively reduce m...
by mataharry Communicator in Getting Data In 04-11-2012
1 3
1
3
cvajs
v4.3 sles 11.1 can you explain for me this transform [csafields] REGEX = ^[^\|]+\|([^\|]+)\|([^\|]+)\|([^\|]+)\|([^...
by cvajs Contributor in Getting Data In 04-11-2012
0 8
0
8
ma_anand1984
My log goes like this. I want all contents between "BeginEvent" and "EndEvent" as a single event. Any help? Will grea...
by ma_anand1984 Contributor in Getting Data In 04-11-2012
0 4
0
4
echalex
Hi, I'm just setting up a deployment server and created a simple app to test it. The app was installed fine on my un...
by echalex Builder in Getting Data In 04-11-2012
0 5
0
5
nkitmitto
All day, I've been watching the amount of events indexed in Splunk go up and down. It stays in the 1.8-1.9 billion e...
by nkitmitto Explorer in Getting Data In 04-10-2012
1 1
1
1
jbsplunk
Hi, I'm getting ready to deploy the splunk Lea-Loggrabber client (32-bit) on RH6 64-bit OS. Would anyone happen to ha...
by jbsplunk Splunk Employee Splunk Employee in Getting Data In 04-10-2012
5 1
5
1
Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

How Edge Processor's Durable Queue Works

Edge Processor sits in one of the most consequential places in any Splunk pipeline: between your data sources ...
Top Solution Authors