Thread Info | |||||
---|---|---|---|---|---|
If a LWF has a large number of files to monitor, what settings can be used to help ensure that consuming/monitoring t...
by
Ron_Naken
Splunk Employee
in
Getting Data In
09-21-2010
|
3
|
2
| |||
Since I usually turned of splunkd service on my local machine and only turn it back on when I need to do some log sea...
by
Stan
New Member
in
Getting Data In
09-21-2010
|
0
|
1
| |||
I just downloaded and installed splunk 4.1.4 and installed on WIN7 laptop. Upon reboot of my system, the CPU pegged a...
by
dexpeterson
Explorer
in
Getting Data In
09-07-2010
|
1
|
8
| |||
I have a fschange stanza configured as such
[fschange:/path/to/file]
disabled = false
pollPeriod = 300
fullEvent =...
by
muebel
SplunkTrust
in
Getting Data In
09-21-2010
|
1
|
3
| |||
I've been using the default "main" index for all my indexing. I'm at the point where I think it would be best to bran...
by
Branden
Builder
in
Getting Data In
09-20-2010
|
1
|
5
| |||
Hi...
I'm trying to import 'thousands' of old event logs into Splunk to setup a searchable database....
I can e...
by
berniefieldhous
Engager
in
Getting Data In
09-20-2010
|
2
|
3
| |||
I'm trying to take data from specific systems and, after indexing it, forward it to a third party for other analysis....
by
Steve_Litras
Path Finder
in
Getting Data In
08-12-2010
|
3
|
3
| |||
Hi,
Now I know you can set the following in indexes.conf maxTotalDataSizeMB = 500000 which sets the max size of th...
by
Josh
Path Finder
in
Getting Data In
09-16-2010
|
1
|
8
| |||
I am writing an app for my team to use. Let's call the app xyz. The app will make use of various inputs, saved search...
by
Branden
Builder
in
Getting Data In
09-20-2010
|
0
|
2
| |||
We're using the unix app to monitor our linux machines. One of the files we need to monitor is /var/log/secure. The u...
by
Peter_B
Explorer
in
Getting Data In
09-20-2010
|
2
|
2
| |||
Hi, I'm using Splunk to index logs which timestamp is in the format Y2010M09D17H10N07S00. As Splunk couldn't understa...
by
liviab
Explorer
in
Getting Data In
09-17-2010
|
2
|
5
| |||
We have a configuration that's been idling for over two days, and instead of processing locations that the tailing pr...
by
parallaxed
Path Finder
in
Getting Data In
06-14-2010
|
2
|
14
| |||
Hello,
We are looking at deploying splunk for our application servers log files, these log files are about 3GB per...
by
iokoluke
New Member
in
Getting Data In
09-17-2010
|
0
|
2
| |||
I have splunk set up on a few redhat boxes, and I am getting duplicate events from them. One event will list the host...
by
muebel
SplunkTrust
in
Getting Data In
09-17-2010
|
0
|
2
| |||
I have records that consist of fairly large (200+ lines, > 20 Kb per record) XML documents.
When I export the resu...
by
pde
Path Finder
in
Getting Data In
09-13-2010
|
0
|
2
| |||
Hi, I'm new to splunk, so my question might be lame. I am trying to setup a splunk lightweight forwarder, my problem ...
by
ultra
Explorer
in
Getting Data In
09-16-2010
|
0
|
1
| |||
One Splunk instance is forwarding data to a receiver, however the receiver is indexing the data and getting the wrong...
by
Caio_Santos
Path Finder
in
Getting Data In
09-15-2010
|
0
|
2
| |||
So I have the following in inputs.conf:
[udp://10005]
connection_host =
index = serverlogs
sourcetype = syslog
dis...
by
tedder
Communicator
in
Getting Data In
09-15-2010
|
0
|
3
| |||
I'm forwarding data from a windows splunk instance to a freebsd. I checked the index that i'm forwarding data to, so ...
by
Caio_Santos
Path Finder
in
Getting Data In
09-14-2010
|
0
|
1
| |||
I am checking out a sample application where an eventtype's search contains "sourcetype=..." . I having difficulty de...
by
dleung
Splunk Employee
in
Getting Data In
09-08-2010
|
1
|
4
| |||
How do I know which index forwarded data goes to receiver instance ? I'm not sure about that, but i've created 2 inde...
by
Caio_Santos
Path Finder
in
Getting Data In
09-14-2010
|
1
|
2
| |||
How do I monitor how often my users are using Splunk?
by
devilears
New Member
in
Getting Data In
09-14-2010
|
0
|
1
| |||
Good Morning,
I have a question that I would love to be answered if possible.
I have written the following x...
by
Ant1D
Motivator
in
Getting Data In
09-13-2010
|
0
|
11
| |||
Hi there,
I would like to know how to handle international character code in Splunk.
The environment I have he...
by
melonman
Motivator
in
Getting Data In
09-02-2010
|
0
|
6
| |||
I've been testing Splunk for several months now, and am consistently having problems with duplicate events appearing ...
by
chjpcert
Explorer
in
Getting Data In
09-07-2010
|
1
|
8
|