Getting Data In

Getting Data In
Community Activity
lutel
Hello All, We are looking for the possiblity of having local authentication for part of the users, and RADIUS authen...
by lutel Explorer in Getting Data In 09-07-2011
0 1
0
1
pstamati
Hi all!. I'm new with Splunk. I´m trying to exclude some events from being indexed but I really don´t know where to s...
by pstamati Path Finder in Getting Data In 09-07-2011
3 8
3
8
RVDowning
Newbie here with an issue. Running Splunk 4.2.2 indexer on Linux and universal forwarders 4.2.2 on Windows 7 machine...
by RVDowning Contributor in Getting Data In 09-07-2011
1 6
1
6
mataharry
I installed 4.2 splunk, and made it a forwarder (not lightweight or universal forwarder) Because I want to do some fi...
by mataharry Communicator in Getting Data In 09-07-2011
3 7
3
7
giovere
I'm trying to change sinkhole directory and configure it so that it will delete files only after 5 days or so. Is the...
by giovere Path Finder in Getting Data In 09-07-2011
1 5
1
5
remy06
I have been monitoring a log file via file monitor input.I disabled the monitoring temporary for a few days but when ...
by remy06 Contributor in Getting Data In 09-07-2011
0 3
0
3
alexander_lucas
If I define this in .../local/indexes.conf [default] coldToFrozenDir = $SPLUNK_DB/frozenArchive Will Splunk roll ...
by alexander_lucas Explorer in Getting Data In 09-06-2011
1 3
1
3
alexander_lucas
Dears, Are there separate fields for: Event received time (when event was received by Splunk); and Parsed (extracted...
by alexander_lucas Explorer in Getting Data In 09-06-2011
1 3
1
3
Branden
I'm thinking about adding certain application server logs to our Splunk environment. At first, it seemed simple: I wo...
by Branden Builder in Getting Data In 09-05-2011
0 4
0
4
hulahoop
If I have a basic input which sets the sourcetype, configuring a timezone offset works great: In inputs.conf: [moni...
by hulahoop Splunk Employee Splunk Employee in Getting Data In 09-03-2011
3 10
3
10
jhallman
Forwarder is in US/Pacific and splunk indexer is in EST. Where do I need to set the timezone so _time has the correct...
by jhallman Explorer in Getting Data In 09-03-2011
0 3
0
3
sseekamp
We have an environment with a mix of light/heavy forwarders, a deployment server, an indexer, and multiple apps. If I...
by sseekamp Explorer in Getting Data In 09-03-2011
0 2
0
2
Steve_Litras
Hi - I'm embarking on a re-organization in my splunk environment. I've come into possession of a couple big x86 box...
by Steve_Litras Path Finder in Getting Data In 09-03-2011
0 2
0
2
alexander_lucas
Host does not get properly extracted for linux_secure (I get the syslog server hostname instead) I have tried many t...
by alexander_lucas Explorer in Getting Data In 09-03-2011
1 2
1
2
cbdick
I have a host that is sending syslog entries with a couple of different formats. I have resolved how to roll multili...
by cbdick Explorer in Getting Data In 09-02-2011
1 1
1
1
cbdick
We use splunk with a single UDP syslog input. Between July 13 and 14, we have found that after a certain set of even...
by cbdick Explorer in Getting Data In 09-01-2011
0 1
0
1
msarro
Hey everyone. I am trying to add a time-format to my props.conf file. The source is a csv file containing multiple ti...
by msarro Builder in Getting Data In 09-01-2011
0 1
0
1
rkarnani
Splunk Team, I'm looking for log management/application profiling from Cisco ASA Firewall. On Firewall, syslog-udp/...
by rkarnani Engager in Getting Data In 08-31-2011
2 3
2
3
stefstef
I'm currently in the process of evaluating Splunk for active directory monitoring. What I'm interested in, is using ...
by stefstef Engager in Getting Data In 08-29-2011
1 3
1
3
liviu_trifoi
Hi guys. I want to push error logs from a silverlight app to our splunk installation. I'm using the splunk RESTful A...
by liviu_trifoi Engager in Getting Data In 08-26-2011
1 3
1
3
pjmenon
I am trying to remove unwanted input source files. Tried clean command Stop splunk splunk clean filename Does not w...
by pjmenon Explorer in Getting Data In 08-26-2011
0 6
0
6
zliu
In my inputs.conf, I have: [monitor://cust/http*/web-*/var/log/modsec-audit.log*] [monitor://cust/http*/web-*/var/...
by zliu Splunk Employee Splunk Employee in Getting Data In 08-26-2011
2 1
2
1
kenison
After reading the docs and looking in forums, I thought I had a understanding of monitor and what it does...I guess n...
by kenison New Member in Getting Data In 08-26-2011
0 2
0
2
samiomer
Hello, Is it possible to forward file attachments between Splunks?
by samiomer Path Finder in Getting Data In 08-26-2011
1 4
1
4
wwillsey
Is there a version for Windows Core or instructions to install on Windows Core (No GUI)?
by wwillsey New Member in Getting Data In 08-25-2011
0 5
0
5
Get Updates on the Splunk Community!

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Pro Tips for .conf26: How to Prep Like a Splunk Veteran

There’s no shortage of incredible content lined up for .conf26 in Denver, from deep-dive technical sessions ...
Top Solution Authors