Getting Data In

Getting Data In
Community Activity
asand100
Firstly I am new to Splunk (so aplogies if this is very simple.) Secondly I have a working snmp file being written t...
by asand100 New Member in Getting Data In 04-15-2012
0 2
0
2
sgarvin55
I want to monitor entire Disk Drives and blacklist all .log files recursively using fschange. The only way I can see ...
by sgarvin55 Splunk Employee Splunk Employee in Getting Data In 04-13-2012
2 5
2
5
gowen
I'm trying to monitor files on a Windows server and it isn't working. I've placed a few stanzas like this into etc/d...
by gowen Path Finder in Getting Data In 04-13-2012
2 7
2
7
I-Man
We are a 90% Windows environment. Since we upgraded to 4.3.1, the WMI log format has changed ever so slightly. While ...
by I-Man Communicator in Getting Data In 04-13-2012
0 1
0
1
jeff
I have the following stansas deployed to lightweight forwarders running Windows: props.conf [WinEventLog:Security] ...
by jeff Contributor in Getting Data In 04-13-2012
0 6
0
6
sahil_singh
Hi, How can one get the host and source IP addresses in the event logs instead of hostname in either places. It is c...
by sahil_singh Explorer in Getting Data In 04-13-2012
0 7
0
7
echalex
Hi, Is there any way of creating indexes on several indexers centrally? For a fairly small indexer-farm, it isn't mu...
by echalex Builder in Getting Data In 04-12-2012
0 2
0
2
khyoung7410
hi universalforwarder receives and send the syslog data to do? If possible, how do?
by khyoung7410 Communicator in Getting Data In 04-12-2012
0 2
0
2
Brian_Osburn
I have a request from a user who wants to get some stats from the Exchange App around specific users. Namely they're...
by Brian_Osburn Builder in Getting Data In 04-12-2012
3 2
3
2
jbirchall1
Is it possible to set up forwarders to index data on the path of the file and a portion of the file name automaticall...
by jbirchall1 New Member in Getting Data In 04-12-2012
0 2
0
2
eugenekogan
As far as I can tell, setting maxVolumeDataSizeMB does not trigger bucket moves and has no impact at all. Does anyone...
by eugenekogan Explorer in Getting Data In 04-12-2012
0 6
0
6
tchristian
When I try to install any app from the zipped file, I get an error like: There was an error processing the upload. L...
by tchristian New Member in Getting Data In 04-12-2012
0 3
0
3
Glenn
Hi, I am using a props/transforms TRANSFORM to add the source (log file) name to the _raw log event line. props.con...
by Glenn Builder in Getting Data In 04-12-2012
0 1
0
1
kenchisho
Hi guys, I have installed Splunk 4.3 on a MAC OSX 10.7. I am trying to index data with non utf encoding. I have tri...
by kenchisho Path Finder in Getting Data In 04-12-2012
0 3
0
3
echalex
Hi, I'm having a weird problem with recognizing timestamps. The actual timestamp looks like this: [2012-04-11 11:24:...
by echalex Builder in Getting Data In 04-12-2012
0 4
0
4
wbfoxii
I have a Universal Forwarder looking at a directory holding our proxy logs. New logs are dumped into the directory e...
by wbfoxii Communicator in Getting Data In 04-12-2012
1 3
1
3
sarah89
please I need help , I deployed a universal forward by following tutorial "distributed deployement manual" The un...
by sarah89 Path Finder in Getting Data In 04-12-2012
1 16
1
16
JPValadas
Hi again, I got one question in filtering and routing to indexer. i got my props like this: pros.conf [WinEven...
by JPValadas Explorer in Getting Data In 04-12-2012
0 9
0
9
sconnors
In our environment (mid-size enterprise with remote sites) we have our primary indexer on dedicated hardware. All dat...
by sconnors Engager in Getting Data In 04-12-2012
0 5
0
5
johnamcafee
We need to index content that may contain in-line gzip (or other compression) content. We do not need to search on th...
by johnamcafee New Member in Getting Data In 04-11-2012
0 1
0
1
Mick
I wanted to see how Splunk would index my data, so I configured it to index a few files into a 'test' index. Now tha...
by Mick Splunk Employee Splunk Employee in Getting Data In 04-11-2012
3 6
3
6
Jason
I'm looking at a Splunk instance right now that is getting 99+% of its data as one particular sourcetype, from two he...
by Jason Motivator in Getting Data In 04-11-2012
1 5
1
5
mataharry
Hi I have a license pool for X Gb per day, and I blow it every almost every single day. How to selectively reduce m...
by mataharry Communicator in Getting Data In 04-11-2012
1 3
1
3
cvajs
v4.3 sles 11.1 can you explain for me this transform [csafields] REGEX = ^[^\|]+\|([^\|]+)\|([^\|]+)\|([^\|]+)\|([^...
by cvajs Contributor in Getting Data In 04-11-2012
0 8
0
8
ma_anand1984
My log goes like this. I want all contents between "BeginEvent" and "EndEvent" as a single event. Any help? Will grea...
by ma_anand1984 Contributor in Getting Data In 04-11-2012
0 4
0
4
Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...
Top Solution Authors