Getting Data In

Getting Data In
Community Activity
klee310
Hi all, I'm testing a setup in which there are two Windows servers. Both Splunk instances also have the Windows app i...
by klee310 Communicator in Getting Data In 04-21-2011
1 3
1
3
ollekax
Well since all searches directed me to splunk i guess this program should be able to help me with my issue. I would ...
by ollekax New Member in Getting Data In 04-21-2011
0 2
0
2
hacktastic
Hello, I'm still trying to get my head around the back end of the new licensing. I'm upgrading about 500 LWFs to 4.2...
by hacktastic Path Finder in Getting Data In 04-21-2011
1 2
1
2
richnavis
Our company uses these to collect error messages from certain sources, and it would be very nice to be able to search...
by richnavis Contributor in Getting Data In 04-21-2011
0 2
0
2
jstockton
I created an App and in my inputs.conf have it calling a Windows batch file to execute an .exe, but the exe seems tha...
by jstockton New Member in Getting Data In 04-21-2011
0 7
0
7
bearrito
Splunk New User here. I am having trouble getting forwarding and receiving working to any degree. On the receiver I...
by bearrito New Member in Getting Data In 04-21-2011
0 2
0
2
carmackd
I have a script that queries a database and outputs the results to a csv file. When the file is finished being writt...
by carmackd Communicator in Getting Data In 04-20-2011
1 1
1
1
williamsweat
Hello, When I stream UDP data to Splunk using a script to pipe Apache access logs via scripts. The splunk server co...
by williamsweat Path Finder in Getting Data In 04-20-2011
1 4
1
4
manuarora
Hi, I have following inputs.conf [script://$SPLUNK_HOME/etc/apps/appa/bin/script1.sh] index = index1 sourcetype = s...
by manuarora Explorer in Getting Data In 04-20-2011
0 4
0
4
Branden
I noticed support for AIX 6.1 as of Splunk 4.2. Great! Then I noticed support for AIX 6.1 taken away with Splunk 4....
by Branden Builder in Getting Data In 04-20-2011
0 2
0
2
travispowell
I read a post on the site describing how an optimum custom log format for Splunk would take the form: <timestamp> ke...
by travispowell Path Finder in Getting Data In 04-19-2011
0 3
0
3
vbumgarner
I believe that if a directory mentioned in a monitor statement is not there when splunk starts up, the directory will...
by vbumgarner Contributor in Getting Data In 04-19-2011
0 1
0
1
trevorford
If I have a 4.2 Universal Forwarder (Windows) installed on a machine that was migrated from 4.1.x and still has the o...
by trevorford New Member in Getting Data In 04-19-2011
0 1
0
1
willthames
My props.conf has: [server] MAX_TIMESTAMP_LOOKAHEAD = 0 SHOULD_LINEMERGE = true #BREAK_ONLY_BEFORE_DATE = true BREAK...
by willthames Path Finder in Getting Data In 04-19-2011
2 7
2
7
Starlette
I have a single source and my main config is based on overided sourcetypes. So is it save to build all configs (FIELD...
by Starlette Contributor in Getting Data In 04-18-2011
0 2
0
2
oscargarcia
Hi, We are indexing a substantial number of XML files. These files have between 30% and 50% of white space that can ...
by oscargarcia Path Finder in Getting Data In 04-15-2011
0 4
0
4
bmayer00
I have the following confs inputs: [monitor:///opt/logs/\*.prd/\*/\*EndAudit.csv] disable = false index = foo pro...
by bmayer00 Engager in Getting Data In 04-15-2011
0 1
0
1
MasterOogway
I am attempting to bring data together from servers sitting in GMT in line with the logs from servers sitting in CMT,...
by MasterOogway Communicator in Getting Data In 04-15-2011
1 3
1
3
brianm1002
I have one splunk indexer that receives data from a variety of hosts. I want to also forward the data coming in from ...
by brianm1002 New Member in Getting Data In 04-15-2011
0 1
0
1
oscargarcia
Hi, We have a system with many indexed small xml files. Is it possible to have a link/view that displays the full co...
by oscargarcia Path Finder in Getting Data In 04-15-2011
0 2
0
2
shanleyj
Hi I'm forwarding logs into Splunk from a database trace file via monitor through a LWF. Example file content is a...
by shanleyj Explorer in Getting Data In 04-15-2011
0 2
0
2
David
I need to figure out how I can gracefully revise data that's already been indexed. My use case is this: We are monit...
by David Splunk Employee Splunk Employee in Getting Data In 04-14-2011
1 2
1
2
suhprano
Can Splunk universal forwarders handle and forward newly created log files? I would like to forward data as raw logs ...
by suhprano Path Finder in Getting Data In 04-14-2011
2 1
2
1
brandnew_users
I think i'm going mad. I'm a brand new user who's eval-ing splunk, seems powerful but i'd like to get all my logs in...
by brandnew_users Explorer in Getting Data In 04-14-2011
0 3
0
3
charlesm
I know there are similar questions, but not exactly and the answers don't seem to apply. Also, I'm a noob so forgive...
by charlesm Explorer in Getting Data In 04-14-2011
0 3
0
3
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...