| I need to watch log files for certain error strings only. Ideally this would be done on the machine that contains th... by sdickson New Member in Getting Data In 07-27-2011 0 1 | 0 | 1 | ||
| I have done 3-4 days of research and have been striking out. Here is the process that I follow. I install the unive... by chrisscott1 New Member in Getting Data In 07-26-2011 0 1 | 0 | 1 | ||
| I'm running into an issue with using the Splunk API and it only returning 30 records. I've searched the Splunk API, ... by Zambonilli Explorer in Getting Data In 07-26-2011 0 2 | 0 | 2 | ||
| I want to be able to push down a single application which contains an inputs.conf to monitor files on a Oracle RAC sy... by approachct Path Finder in Getting Data In 07-25-2011 0 1 | 0 | 1 | ||
| My Splunk instance is constantly indexing data 24*7, but I've noticed some gaps in the indexed data timeline recently... by mctester Communicator in Getting Data In 07-25-2011 3 3 | 3 | 3 | ||
| I'm trying to define multiple REGEX for one sourcetype. Because the events can vary massively I need to have differen... by Drainy Champion in Getting Data In 07-22-2011 2 1 | 2 | 1 | ||
| Problem summary: After Splunk update from 4.2 to 4.2.1, one (and only one) of the indexes started a warm to cold a... by ruiaires Path Finder in Getting Data In 07-22-2011 0 4 | 0 | 4 | ||
| Hey! Is it possible to configure SplunkUniversalForwarder to receive data by udp and send this data to indexer? How?... by Vladimir Path Finder in Getting Data In 07-22-2011 0 2 | 0 | 2 | ||
| I have a large number of files (going by the thousands) that I only need to index once, and since I want to know when... by rf2010 New Member in Getting Data In 07-21-2011 0 2 | 0 | 2 | ||
| Having trouble with CRC, I set my inputs to use crcSalt = , which I understood would use the full path of the input,... by chca Path Finder in Getting Data In 07-21-2011 1 1 | 1 | 1 | ||
| Hello Splunk Community, I uploaded custom CSV files to Splunk for indexing. The CSV Header for each file is being in... by srsava New Member in Getting Data In 07-21-2011 0 4 | 0 | 4 | ||
| I used the web interface to add some monitors, but I need to customize them. I opened the inputs.conf file in the loc... by chca Path Finder in Getting Data In 07-21-2011 0 2 | 0 | 2 | ||
| Hi guys. I am having some trouble routing data from one source to different indexes. Here is my setup inputs.conf ... by kenchisho Path Finder in Getting Data In 07-19-2011 0 3 | 0 | 3 | ||
| Is there a way to configure Splunk to enforce indexing quoatas by Host? e.g. Do not index more than 250MB per day fo... by NK_1 Path Finder in Getting Data In 07-18-2011 3 3 | 3 | 3 | ||
| I have a strange problem. When I install the universal forwarder on my log server and perform a netstat -l I do not ... by sab057 Explorer in Getting Data In 07-15-2011 2 4 | 2 | 4 | ||
| I have been reading link:Splunk 4.2 Universal Forwarder *nix Why does a universal forwarder need the entire *nix app... by byronschwab Engager in Getting Data In 07-15-2011 0 1 | 0 | 1 | ||
| I am trying to write a custom search module in python that will check the host field of event data in a comprehensive... by msantoro1 Explorer in Getting Data In 07-14-2011 0 4 | 0 | 4 | ||
| Not new to Splunk, but new to 4.2.2. I had setup a forwarder and manually entered specific paths to monitor: /p01/fo... by _z_ Explorer in Getting Data In 07-14-2011 1 7 | 1 | 7 | ||
| Hello all, We have Nessus running on a Linux server which also has a Splunk Heavy Forwarder 4.1.8. We have the Nessu... by I-Man Communicator in Getting Data In 07-14-2011 1 2 | 1 | 2 | ||
| Most of our systems use rsyslog for logging, and log their events over UDP to a central splunk server. This works fi... by tcutts New Member in Getting Data In 07-13-2011 0 2 | 0 | 2 | ||
| hello I need help. for masking text in .log file with splunk forwarder i have 16 numbers like 1111-2222-3333-4444 I ... by gchkhikvadzecar Engager in Getting Data In 07-13-2011 1 1 | 1 | 1 | ||
| Hi, I saw several posts about this problem, but none with a valid answer. My problem is that I have a running Splunk... by imbuto New Member in Getting Data In 07-13-2011 0 1 | 0 | 1 | ||
| I have a 'dev/tst' db host.. but have dev app indexer and tst app indexer. Is there a way to configure a single forwa... by _z_ Explorer in Getting Data In 07-12-2011 1 2 | 1 | 2 | ||
| I have several groupwise servers running forwarders to a single index server. For the most part the data is arriving... by Cagey Engager in Getting Data In 07-12-2011 1 1 | 1 | 1 | ||
| Hi all, I've studied that Splunk is capable of retenting the original logs feed in to it, also audit the changes if ... by infosec_skrc Explorer in Getting Data In 07-12-2011 0 2 | 0 | 2 |