Getting Data In

Getting Data In
Community Activity
kinkdotcom
I have an alert set up that surfaces suspicious activity by ip addresses which triggers an extremely simple shell scr...
by kinkdotcom New Member in Getting Data In 02-21-2012
0 1
0
1
grahamkenville
We have a number of MS SQL Server clusters with the Splunk Universal Forwarder installed. We would like to index th...
by grahamkenville Engager in Getting Data In 02-21-2012
0 1
0
1
kml_uvce
I have an output lifesize_cdr: INFO 24,16,8CC 9-107-Photon,172.20.129.30,,,,2012-02-07 16:22:21,2012-02-07 16:22:21,...
by kml_uvce Builder in Getting Data In 02-21-2012
0 5
0
5
ohl
Is there any way to change the scale on the message meter in the Exchange app? We normally generate about 10k emails...
by ohl New Member in Getting Data In 02-21-2012
0 1
0
1
ssingh5
Hi, I have configured following parameters for testing the log Archiving for one of my index named "os". But it is n...
by ssingh5 Path Finder in Getting Data In 02-21-2012
0 4
0
4
raki
I have a Cisco ACS serving radius requests for VPN users. The syslog is configured for splunk and is able to receive ...
by raki New Member in Getting Data In 02-21-2012
0 4
0
4
yrosario
We would like more information on how to setup splunk alert emails with smtp exchange 2007. If there are any suggesti...
by yrosario Engager in Getting Data In 02-21-2012
0 3
0
3
astepanov
Hi all, Splunk adds one hour to timestamp, when indexing logs. Example of my logs: [ 21/Feb/2012 1:05:32.306 PM]...
by astepanov Explorer in Getting Data In 02-21-2012
0 7
0
7
Splunker
Folks, Running Splunk v4.3 and trying to understand this phenomenon. In transforms.conf, something like this: [tran...
by Splunker Communicator in Getting Data In 02-18-2012
0 2
0
2
RalphT
By source type or file, I changed the line breaking setting but it never takes effect. On my local test system it wor...
by RalphT New Member in Getting Data In 02-18-2012
0 1
0
1
leiniao
Requirment Drop events before they get sent to the splunk indexer. Want to just send the lines with "Authenticatio...
by leiniao Explorer in Getting Data In 02-17-2012
1 3
1
3
chris
A universal forwarder asks me to start splunk when i try to use the cli. Has anyone else experienced this or similar ...
by chris Motivator in Getting Data In 02-17-2012
2 2
2
2
Glenn
I need to be able to add some information from the Splunk metadata (host and source) into the raw log. I'm looking at...
by Glenn Builder in Getting Data In 02-17-2012
2 4
2
4
jchensor
I was wondering if you can assign a search-time extracted field one value and then later, in a stanza that will be pr...
by jchensor Communicator in Getting Data In 02-16-2012
0 5
0
5
asarolkar
We are using the Universal lightforwarder on a linux box and pushing the monitored output for the several log files ...
by asarolkar Builder in Getting Data In 02-15-2012
1 6
1
6
jfaldmo
I have setup a props.conf with: [host::server*] TRANSFORMS-movetonewindex = newindex And a transforms.conf with: [n...
by jfaldmo Explorer in Getting Data In 02-15-2012
0 1
0
1
MrSplunksta
Hi ! Since I have installed splunk-4.1.2-79191-x64-release as a forwarder on a Windows 64 i'm getting several instanc...
by MrSplunksta Path Finder in Getting Data In 02-15-2012
0 13
0
13
ciandro84
Does the deployment server come with a universal forwarder of its own already installed on it? I have a central index...
by ciandro84 Engager in Getting Data In 02-15-2012
0 3
0
3
mloven
Hi all! Ok, so here's my situation. All Splunk software listed below is v4.3. I've installed a forwarder on a linu...
by mloven Path Finder in Getting Data In 02-14-2012
2 12
2
12
huaraz
I have a logfile with the following format: LOG: : ; : ; ..... If I had only one key value pair I think could do ...
by huaraz Explorer in Getting Data In 02-12-2012
0 2
0
2
emiller42
I'm attempting to index the gc.log coming from a tomcat installation, and I can't seem to get it to linemerge properl...
by emiller42 Motivator in Getting Data In 02-12-2012
5 2
5
2
KGolomb
The CheckPoint LEA Application (lea_loggrabber) seems to be grabbing every field that appears in the logs without pu...
by KGolomb Engager in Getting Data In 02-10-2012
1 4
1
4
benzieb
I've just configured my first Splunk server (ubuntu 11.04) with snmptrapd logging to /var/log/snmp-traps as per http:...
by benzieb Engager in Getting Data In 02-10-2012
2 2
2
2
Ferrari
There are log files in a directory and all of them were forwarded to indexer except the files starting with SystemOut...
by Ferrari Explorer in Getting Data In 02-10-2012
0 1
0
1
fernandoandre
Hi, I need help with the following. I have two distinct services in different machines. I want to send their logs/in...
by fernandoandre Communicator in Getting Data In 02-09-2012
0 3
0
3
Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...
Top Solution Authors