Getting Data In

Getting Data In
Community Activity
laurentjehu
Hi, I'm testing Splunk to monitoring the log of an application. The logs are generated with log4j. When I configure ...
by laurentjehu Engager in Getting Data In 09-14-2011
0 1
0
1
jordans
ERROR ExecProcessor - Ignoring: "\\C:\Program Files\Splunk\etc\apps\test\bin\intodns.py" This new scripted input I ...
by jordans Path Finder in Getting Data In 09-13-2011
0 2
0
2
fox
Running 4.2.1, we are monitoring many csv files that differ on listed fields. We have splunk configured to dynamicall...
by fox Path Finder in Getting Data In 09-13-2011
0 2
0
2
mataharry
Hi I am trying to have splunk monitoring a log file. But splunk indexed it once, and since is skipping it every time...
by mataharry Communicator in Getting Data In 09-13-2011
3 3
3
3
maverick
Currently, I'm using WMI to pull WinEvents from 17 Windows running on VMs. They are each the exact same and were buil...
by maverick Splunk Employee Splunk Employee in Getting Data In 09-12-2011
0 3
0
3
maverick
I am feeding a log event into Splunk that has a julian date and a time that consists of seconds since midnight: 245...
by maverick Splunk Employee Splunk Employee in Getting Data In 09-12-2011
2 4
2
4
giovere
I'm trying to make indexes retire after 60 seconds, here is how my indexes.conf looks like: [default] frozenTimePeri...
by giovere Path Finder in Getting Data In 09-12-2011
0 4
0
4
I_am_Jeff
We have several NetApps that require log retention. Getting log events to Splunk appears to be an odd configuration....
by I_am_Jeff Communicator in Getting Data In 09-09-2011
0 2
0
2
jaoui
If i am setting up a heavy forwarder to monitor directories and tag indexes, do i need to create an indexes.conf on i...
by jaoui Path Finder in Getting Data In 09-09-2011
0 1
0
1
jaoui
If i am setting up a heavy forwarder to monitor directories and tag indexes, do i need to create an indexes.conf on i...
by jaoui Path Finder in Getting Data In 09-08-2011
0 4
0
4
gnovak
I have a bunch of logs I've added to splunk and created sourcetypes for these logs. These logs are updated once a wee...
by gnovak Builder in Getting Data In 09-08-2011
0 1
0
1
gnovak
I have a bunch of logs I've added to splunk and created sourcetypes for these logs. These logs are updated once a we...
by gnovak Builder in Getting Data In 09-07-2011
0 2
0
2
lutel
Hello All, We are looking for the possiblity of having local authentication for part of the users, and RADIUS authen...
by lutel Explorer in Getting Data In 09-07-2011
0 1
0
1
pstamati
Hi all!. I'm new with Splunk. I´m trying to exclude some events from being indexed but I really don´t know where to s...
by pstamati Path Finder in Getting Data In 09-07-2011
3 8
3
8
RVDowning
Newbie here with an issue. Running Splunk 4.2.2 indexer on Linux and universal forwarders 4.2.2 on Windows 7 machine...
by RVDowning Contributor in Getting Data In 09-07-2011
1 6
1
6
mataharry
I installed 4.2 splunk, and made it a forwarder (not lightweight or universal forwarder) Because I want to do some fi...
by mataharry Communicator in Getting Data In 09-07-2011
3 7
3
7
giovere
I'm trying to change sinkhole directory and configure it so that it will delete files only after 5 days or so. Is the...
by giovere Path Finder in Getting Data In 09-07-2011
1 5
1
5
remy06
I have been monitoring a log file via file monitor input.I disabled the monitoring temporary for a few days but when ...
by remy06 Contributor in Getting Data In 09-07-2011
0 3
0
3
alexander_lucas
If I define this in .../local/indexes.conf [default] coldToFrozenDir = $SPLUNK_DB/frozenArchive Will Splunk roll ...
by alexander_lucas Explorer in Getting Data In 09-06-2011
1 3
1
3
alexander_lucas
Dears, Are there separate fields for: Event received time (when event was received by Splunk); and Parsed (extracted...
by alexander_lucas Explorer in Getting Data In 09-06-2011
1 3
1
3
Branden
I'm thinking about adding certain application server logs to our Splunk environment. At first, it seemed simple: I wo...
by Branden Builder in Getting Data In 09-05-2011
0 4
0
4
hulahoop
If I have a basic input which sets the sourcetype, configuring a timezone offset works great: In inputs.conf: [moni...
by hulahoop Splunk Employee Splunk Employee in Getting Data In 09-03-2011
3 10
3
10
jhallman
Forwarder is in US/Pacific and splunk indexer is in EST. Where do I need to set the timezone so _time has the correct...
by jhallman Explorer in Getting Data In 09-03-2011
0 3
0
3
sseekamp
We have an environment with a mix of light/heavy forwarders, a deployment server, an indexer, and multiple apps. If I...
by sseekamp Explorer in Getting Data In 09-03-2011
0 2
0
2
Steve_Litras
Hi - I'm embarking on a re-organization in my splunk environment. I've come into possession of a couple big x86 box...
by Steve_Litras Path Finder in Getting Data In 09-03-2011
0 2
0
2
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...
Top Solution Authors