Getting Data In

Getting Data In
Community Activity
sneuser
Hello, How could we avoid duplicate reporting of the same host? Hosts (≥ 3) host Count Last Update 1 Tes...
by sneuser New Member in Getting Data In 01-31-2012
0 2
0
2
the_wolverine
I have some data in my index that I don't want. How can I get rid of them?
by the_wolverine Champion in Getting Data In 01-31-2012
10 4
10
4
remy06
I've recently upgraded the forwarder to a universal forwarder on our app server.I'm collecting windows event logs as ...
by remy06 Contributor in Getting Data In 01-31-2012
0 5
0
5
sonicZ
Hey, I am looking to add a static field "instance=testdrive" to all results from a source input with td-idp-manager ...
by sonicZ Contributor in Getting Data In 01-31-2012
0 3
0
3
ngcgoon
I haven't seen any conclusive documentation on this, however does the Universal forwarder support Apps like the Splun...
by ngcgoon Explorer in Getting Data In 01-30-2012
1 3
1
3
matthewpowell
The "active-only" feature doesn't seem to work in Splunk 4.3: # splunk add monitor /var/log/messages -active-only tr...
by matthewpowell Engager in Getting Data In 01-30-2012
1 3
1
3
jcott28
UPDATE: I just downloaded the sourcecode from the SVN repository and made the modification myself and rebuilt the jar...
by jcott28 Explorer in Getting Data In 01-30-2012
2 1
2
1
Vladimir
Hi, I've configured a directory for monitoring in inputs.conf ([monitor://path_to_dir]) and separated index for this...
by Vladimir Path Finder in Getting Data In 01-30-2012
0 6
0
6
Nik
Guys, I currently run splunk on a Windows box. Is it possible for me to move the database from Windows to Linux (Cent...
by Nik New Member in Getting Data In 01-29-2012
0 2
0
2
gharpe2
I have the Splunk for Windows app installed but it is collecting syslog UDP:514 data as well. How do I exclude the s...
by gharpe2 Explorer in Getting Data In 01-28-2012
0 1
0
1
Flynt
My Splunk won't start due to this error! What do I do? ERROR: failed to load index config: 'maxTotalDataSizeMB' tag...
by Flynt Splunk Employee Splunk Employee in Getting Data In 01-27-2012
2 3
2
3
merritsa
Hello, I have several questions/issues with the Splunk API, so I'll try to keep this short and concise. First - doe...
by merritsa Path Finder in Getting Data In 01-27-2012
3 12
3
12
pheezy
According to this document: Specifyinputpathswithwildcards The asterisk wildcard matches anything in that specific ...
by pheezy Explorer in Getting Data In 01-26-2012
1 3
1
3
mark
Hi All, Question about reindexing indexed data: I have a legacy 4.2.x splunk server running. Its set to index all d...
by mark Path Finder in Getting Data In 01-26-2012
0 2
0
2
jdibble
We've recently changed out our servers and when I use the searches against these new hosts using my user I am not get...
by jdibble Explorer in Getting Data In 01-26-2012
0 7
0
7
bherbert
So, I've installed and configured the Splunk forward on my Intranet Server. I'm trying to get the IIS logs from \Win...
by bherbert Engager in Getting Data In 01-26-2012
0 3
0
3
ngcgoon
Does anyone know how we can use the timestamp of the file from the operating system as the timestamp for events? For ...
by ngcgoon Explorer in Getting Data In 01-26-2012
0 4
0
4
acalvo
We're trying to forward data to a syslog server from a splunk server. However, seems that the hostname and process id...
by acalvo Explorer in Getting Data In 01-25-2012
2 6
2
6
nisse
I have a Splunk indexer (splunk-4.0.9-74233-linux-2.6-x86_64.rpm) sending cooked data to a Splunk forwarder (active_g...
by nisse Explorer in Getting Data In 01-25-2012
2 5
2
5
Nicholas_Key
[1] May I know what are the differences between using monitor or fschange? [2] Is there a documentation about fschan...
by Nicholas_Key Splunk Employee Splunk Employee in Getting Data In 01-25-2012
2 2
2
2
Branden
I've seen a number of posts about this with varied responses. Here's what I'm trying to do: We have some web acces...
by Branden Builder in Getting Data In 01-25-2012
0 7
0
7
sscandoit
Hi, We have a cron job which periodically updates the lookup file. The file name is of the format lookup_mmddyyyy.cs...
by sscandoit Explorer in Getting Data In 01-25-2012
1 2
1
2
dzilk
I am new to splunk and am trying to set up a monitored directory. It appears that when browsing for an existing dire...
by dzilk Engager in Getting Data In 01-25-2012
1 2
1
2
fk319
We are converting from a single Splunk instantance to a cluster. At this time we are also implementing Universal For...
by fk319 Builder in Getting Data In 01-25-2012
0 5
0
5
awalesa
Hi, I've tried everything. I have read all the answers and docs. A cannot force splunk indexer to forward all events...
by awalesa New Member in Getting Data In 01-25-2012
0 12
0
12
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...
Top Solution Authors