Getting Data In

Getting Data In
Community Activity
baerrach
My input from log4j looks like 2011-07-28 15:45:25,402 INFO ... And splunk is indexing it as 28/07/2011 16:15:...
by baerrach Path Finder in Getting Data In 10-13-2011
0 10
0
10
mikefoti
I setup a new Splunk receiver today. Setup a TCP listenner on 9993, wasn't sure what sourceType so selected Syslog, t...
by mikefoti Communicator in Getting Data In 10-13-2011
0 1
0
1
hewhib
Guys, Just wondering if you could help me... When I go to add a scripted input for my Splunk App I get the followi...
by hewhib Explorer in Getting Data In 10-12-2011
1 4
1
4
jonathan_lam
For a single monitor in inputs.conf, is it possible to add multiple index names? index = index1, index2 Basically, ...
by jonathan_lam Explorer in Getting Data In 10-11-2011
0 6
0
6
sushildabare
Universal forwarder is installed in linux server spwdfvml0247. In this we have below folders exe,gen,global,profile,p...
by sushildabare Path Finder in Getting Data In 10-11-2011
0 9
0
9
Megamuch
While testing out Splunk I wanted to see if I could easily create a custom input into splunk using ncat and the UDP s...
by Megamuch Engager in Getting Data In 10-11-2011
2 5
2
5
firasarabo
Hi, I want to prevent DEBUG logging from bieng indexed by the splunk indexers. we use light weight forwarders on bot...
by firasarabo Path Finder in Getting Data In 10-11-2011
5 14
5
14
sushildabare
Universal forwarder is installed in linux server spwdfvml0247. spwdfvml0247:/usr/sap/IX4/SYS # ll [we have below fi...
by sushildabare Path Finder in Getting Data In 10-11-2011
0 1
0
1
cwacha
Actual Situation: A Heavy Forwarder with the [batch://] stanza configured using default values is reading files from...
by cwacha Path Finder in Getting Data In 10-10-2011
0 1
0
1
ajparagas
I have configured my syslog-ng.conf file as follows; # # This should behave pretty much like the original syslog on ...
by ajparagas Engager in Getting Data In 10-10-2011
0 1
0
1
Dark_Ichigo
I am currently indexing large amounts of data and need to restart Splunkd and SplunkWeb! Will Splunk continue indexi...
by Dark_Ichigo Builder in Getting Data In 10-09-2011
0 2
0
2
randommac
Hello, I am trying to receive syslog messages from another host over the network using tcp. I am receiving periodic...
by randommac Engager in Getting Data In 10-08-2011
1 3
1
3
maverick
My understanding is that a retention policy operates on the events in my cold buckets, meaning that when data grows b...
by maverick Splunk Employee Splunk Employee in Getting Data In 10-07-2011
0 1
0
1
JensT
Hello, is it possible in Splunk 4.2.3+ to have separate Inputs, Props and Transforms per App? Example: App1: Listen...
by JensT Communicator in Getting Data In 10-07-2011
0 3
0
3
Greg_LeBlanc
I am having a difficult time extracting the correct timestamp from a specific log. As you can see below, the beginni...
by Greg_LeBlanc Path Finder in Getting Data In 10-06-2011
2 12
2
12
ephemeric
Am I just missing something or being stupid or are there no persistent queues when using Splunk2Splunk with SSL? I s...
by ephemeric Contributor in Getting Data In 10-06-2011
1 2
1
2
dswanson99
I have a series of servers that run apache that serve up the same url via post 99% of the time and in high volume. I...
by dswanson99 Path Finder in Getting Data In 10-06-2011
0 3
0
3
garfieldconnoll
Hi, So we've 2,000 XP machines generating c.20GB of WinEventLogs. For compliance reasons, we want to log it central...
by garfieldconnoll Explorer in Getting Data In 10-05-2011
0 2
0
2
triptrops
Hi All, I am a newbie on Splunk and I am trying to setup a Splunk server and a Splunk Light forwarder to forward dat...
by triptrops Explorer in Getting Data In 10-05-2011
0 4
0
4
mehmettecer
Hi guys, Here is my issue: I have 2 rsyslog servers that are in production in redundant setup. Other servers forward...
by mehmettecer Explorer in Getting Data In 10-04-2011
0 1
0
1
andyspusm
Hi, I am trying to index some processing data from Urchin and having trouble with timestamp recognition and line bre...
by andyspusm Explorer in Getting Data In 10-04-2011
0 5
0
5
efelder
What config file defines where the output.csv file gets stored by default into $SPLUNK_HOME/var/run/splunk?
by efelder New Member in Getting Data In 10-04-2011
0 1
0
1
twinspop
Windows 2003 with SUF, inputs.conf: [monitor://C:\WINNT\system32\LogFiles\HTTPERR] disabled = false sourcetype = iis...
by twinspop Influencer in Getting Data In 10-04-2011
5 6
5
6
Starlette
I have a tcp port as input ( and 2 devices are sending data) and its showing up in de deployment monitor (4.2 centos ...
by Starlette Contributor in Getting Data In 10-04-2011
0 2
0
2
colin_ewen
I'm running into an issue with Splunk ignoring the timestamp in a specific log and just using current indexing time. ...
by colin_ewen New Member in Getting Data In 10-03-2011
0 5
0
5
Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...
Top Solution Authors