Thread Info | |||||
---|---|---|---|---|---|
Hi All,
Does anyone know if it's possible to take logs that have been grabbed from Windows WMI and indexed, and th...
by
Scarecrowddb
Explorer
in
Getting Data In
03-14-2011
|
0
|
1
| |||
I have installed Splunk as a forwarder/light forwarder on a few of our Win2003 x86 servers as a test and am receiving...
by
ccit
Engager
in
Getting Data In
11-16-2010
|
0
|
2
| |||
i have the lea-loggrabber.sh script working well and reliably getting all new logs from checkpoint cma into splunk. I...
by
EricPartington
Communicator
in
Getting Data In
03-12-2011
|
0
|
2
| |||
I am not very familiar with Splunk and syslog servers in general, but I am trying to learn. There is a "Broadcast on ...
by
Pierre
Engager
in
Getting Data In
03-10-2011
|
0
|
3
| |||
I recently copied the splunk-forwarder.license details mentioned in our indexer to splunk.license (into one of our fo...
by
heterodyned
Path Finder
in
Getting Data In
01-31-2011
|
1
|
3
| |||
At a few customers now I have seen a 1MB (forwarder) license with an expiration of early March. I'm not sure where th...
by
Jason
Motivator
in
Getting Data In
03-01-2011
|
2
|
9
| |||
Hi folks,
I'd like to route WMI logs to different indexes based off the host name (I have a few environments)
G...
by
Yancy
Path Finder
in
Getting Data In
04-03-2010
|
2
|
10
| |||
2011-03-09T11:21:34-04:00 ab-wtsk-mg3200-2 [Src=10.157.32.26/49842 Dst=4070 PType=6] ErrMgs=1 Cid=23: 1 RTP packets l...
by
Joel_Gerber
Explorer
in
Getting Data In
03-09-2011
|
0
|
2
| |||
Hi
I've enabled the script input /opt/splunk/etc/apps/unix/bin/rlog.sh to read audit events.
However I noticed ...
by
remy06
Contributor
in
Getting Data In
03-04-2011
|
0
|
2
| |||
I have Splunk running on a Linux server and I need to index WMI-based events, like perfmon data, from my Windows serv...
by
maverick
Splunk Employee
in
Getting Data In
09-15-2010
|
0
|
6
| |||
I have activity files from a vpn radius server and I'd like to label the fields as they go into splunk... I'm not eve...
by
udiggity
New Member
in
Getting Data In
03-07-2011
|
0
|
2
| |||
Our Splunk environment has multiple indexes, with role restrictions on index access.
I want to allow users to uplo...
by
cfergus
Path Finder
in
Getting Data In
03-08-2011
|
0
|
1
| |||
I have a perpetual Enterprise license and having not been having any issues until the today when I started to see a m...
by
Ellen
Splunk Employee
in
Getting Data In
03-02-2011
|
6
|
2
| |||
I have a csv tab-delimited file with entries that looks like this:
GPDB20A LTO3 L03 03/08/11 06:01:20 1299592...
by
rasingh
Path Finder
in
Getting Data In
03-08-2011
|
1
|
1
| |||
I am trying to filter with many transform statements. I believe everything is configured correctly. But I get ALL eve...
by
neusse
Path Finder
in
Getting Data In
03-01-2011
|
0
|
3
| |||
I only want to index the last 365 days of data. Can this be done in Splunk 4.1? Any data older than one year should b...
by
coryjackson
New Member
in
Getting Data In
03-07-2011
|
0
|
2
| |||
I have one Splunk receiver set up and several forwarders (forwarders using free version). About 9 of my hosts are lis...
by
lmalhoit
Explorer
in
Getting Data In
02-17-2011
|
0
|
4
| |||
Has anybody dealt with splunking Windows Robocopy.exe logs? I'm about to dive into it, and am looking for prior art. ...
by
anewell
Path Finder
in
Getting Data In
03-01-2011
|
0
|
1
| |||
Hello folks,
I'm trying to puzzle out getting around SPL-34965 (WMI not load balancing), not inundating a single i...
by
hacktastic
Path Finder
in
Getting Data In
03-04-2011
|
0
|
1
| |||
I'm indexing a CSV file and I just can't get Splunk to extract any fields or apply the proper sourcetype to the event...
by
erga00
Path Finder
in
Getting Data In
06-25-2010
|
3
|
7
| |||
Hello,
I am trying to pick up to files in specific directories under different sourectypes.
[monitor:///app/em...
by
Hazel
Communicator
in
Getting Data In
04-19-2010
|
0
|
10
| |||
We want to write an program to gather logging information from our HP NonStop system log files, both OSS and Guardian...
by
ticsoftware
New Member
in
Getting Data In
03-03-2011
|
0
|
2
| |||
Hi,
I have a sourcetype where i defined the field names in the transforms.conf
Transforms.conf
[my_parse]
...
by
cramasta
Builder
in
Getting Data In
02-15-2011
|
0
|
4
| |||
Hi,
How can I delete old hosts from web interface (all indexed data) in search window?
Thanks in advance
by
mudricd
Explorer
in
Getting Data In
10-09-2010
|
2
|
4
| |||
I have some firewalls and stuff like that send logs to my Splunk server (using normal syslog at the moment). For now ...
by
fisk12
Path Finder
in
Getting Data In
11-10-2010
|
1
|
3
|