Thread Info | |||||
---|---|---|---|---|---|
Hi Splunk Gurus
We have problem with Splunk on Windows. Windows sends way to many events and logs to splunk indexe...
by
nitinthakur
New Member
in
Getting Data In
01-24-2012
|
0
|
3
| |||
Hello,
I have been try to configure the windows app to display data from additional hosts, but without success.
...
by
davidfreer
New Member
in
Getting Data In
11-21-2011
|
0
|
1
| |||
I have a UF sending logs to my indexer. The UF receives logs, via syslog, from several other systems. All my UFs, ind...
by
I_am_Jeff
Communicator
in
Getting Data In
01-13-2012
|
0
|
3
| |||
We have some Cisco devices that are sending syslog via port 514 natively (no splunk forwarder installed, obviously). ...
by
aferone
Builder
in
Getting Data In
01-18-2012
|
2
|
21
| |||
I'm testing Splunk with the following configuration: Splunk 4.3 indexer and Splunk Universal Forwarder 4.3 on a separ...
by
scaldwell1
New Member
in
Getting Data In
01-18-2012
|
0
|
1
| |||
I am performing the following test in my env,
props.conf [newcsvtest] REPORT-newcsvtest = newcsvtest SHOULD_LINEME...
by
schava2
Explorer
in
Getting Data In
01-22-2012
|
0
|
1
| |||
Dear Colleagues,
I am configuring Splunk to listen my File Server in the WMI Security Events. Splunk is listening ...
by
mgaleti
New Member
in
Getting Data In
12-05-2011
|
0
|
1
| |||
I was running a cold to frozen script that moved the forzen files into a separate directory per index.
/opt/splun...
by
imacdonald2
Path Finder
in
Getting Data In
01-20-2012
|
0
|
1
| |||
I have noticed that universal forwarders receiving data from a high-traffic input will fail to distribute events even...
by
hexx
Splunk Employee
in
Getting Data In
11-30-2011
|
3
|
2
| |||
I asked my Firewall admin to change the port for syslog to the Splunk indexer.
He changed it from 514 to 1514.
...
by
hartfoml
Motivator
in
Getting Data In
01-18-2012
|
0
|
2
| |||
My props and transforms.conf work fine and I am able to see the fields on the GUI of search heads ( We are running sp...
by
desi-indian
Path Finder
in
Getting Data In
01-09-2012
|
0
|
4
| |||
Situation:
I log into to splunk and find that data is not present when it should be. I log into the client machine...
by
jgauthier
Contributor
in
Getting Data In
10-28-2011
|
0
|
9
| |||
I've already got my single indexer spec'd to handle under 100Gigs a day and it meets the requirements. However i am g...
by
Chris_R_
Splunk Employee
in
Getting Data In
05-19-2010
|
2
|
3
| |||
What are some of the methods that I can remove the header row after running the 'outputcsv' command in my search?
...
by
efelder0
Communicator
in
Getting Data In
01-19-2012
|
1
|
2
| |||
I've configured my splunk to recieve data from syslog via udp. The application uses a SyslogAppender in it's log4j co...
by
rSteinbrenner
New Member
in
Getting Data In
01-18-2012
|
0
|
2
| |||
Hi,
I'm a splunk newbie. I want to collect data via snmp and display it on charts/graphs. Does the scripted input ...
by
a212830
Champion
in
Getting Data In
01-19-2012
|
0
|
1
| |||
After an upgrade from 4.2.4 to 4.3 on Windows 2008 R2 Server (64bit) I get the following error after the login:
50...
by
FRoth
Contributor
in
Getting Data In
01-19-2012
|
0
|
3
| |||
Hi Guys -
I'm trying to remove "DEBUG" messages from ALL inputs. What do I put in props.conf to apply a transform...
by
tewner
Explorer
in
Getting Data In
01-19-2012
|
1
|
2
| |||
Why i use "add forward-server" is work, but "add search-server" failed?
[root@proxy splunkforwarder]# bin/splunk h...
by
haway
Engager
in
Getting Data In
01-17-2012
|
1
|
2
| |||
Hi guys,
Is it possible to limit a splunk receiver via host wildcard.
So curently I have in inputs.conf [splunk...
by
mark
Path Finder
in
Getting Data In
01-18-2012
|
3
|
1
| |||
Is it possible for Splunk to natively run a search against a remote Splunk REST API from within a search? For example...
by
mundus
Path Finder
in
Getting Data In
01-18-2012
|
1
|
1
| |||
Hi, I have a requirement to create a dashboard view of events occuring from Friday last week to Thrusday running week...
by
theertpr
Explorer
in
Getting Data In
01-18-2012
|
0
|
1
| |||
Is there a way, in the GUI, to edit props.conf after creating a new source (and after indexing)? If not, where can I ...
by
ehs
New Member
in
Getting Data In
01-17-2012
|
0
|
1
| |||
Does data indexed in two separate indexes count twice against the license limit?
by
steve
Path Finder
in
Getting Data In
01-17-2012
|
0
|
2
| |||
I was wondering if anyone is currently using Splunk forwarders as the means by which they receive all log data and th...
by
jaoui
Path Finder
in
Getting Data In
04-21-2011
|
0
|
5
|