I just loaded Splunk 6.2.3 and am forwarding event log events from my laptop running Windows 7. Everything looks OK except I cannot see any "EventLogDescription" datain Splunk. Was this a...
Hi, I'm new to Splunk.
I signed up for the Cloud trial.
When I first logged in I was presented with a "file upload" form to add datainto Splunk.
Ican't seem to find that form now (after a f...
...ourcetype=DataSource event="GRANTED"
| stats max(_time) AS lastUsed by Username
| rename Username AS samAccountName ]
So I get my lookup list of users, start the subsearch pull back a l...
...is-pic\PM\PMLog\PMLog.txt20111126
\\aaasvr\iis-pic\PM\PMLog\PMLog.txt20111128
\\aaasvr\iis-pic\PM\PMLog\PMLog20111128.txt
but in my source data, only one file (\\aaasvr\iis-pic\P...
Hi! i have configred ubuntu machine to send authentication log to my splunk instance using syslog. But i found just the failed auth logs and other logs with the field " pam_unix(c...
...The difference with these events compared to the ones with my new source type is that now Splunk tells me it found 133 events but Ican't see them, with the new source type Splunk doesn't find any e...
...ight source type, and for some reason Ican'tfind the datainput under "Datainputs" to edit it.
If I want to go to Add Data > Forward it tells me that "There are currently no forwarders c...
HI everyone,
I usually run report month by month from Januari untill now (and i still have the report), and now i want to get my March dan May data to review it but the no data at all. I tried r...
...anager can ifind a setting or restriction that would limit me from viewing the data. Ican'tfind anything in the free documentation that indicates the free version only lets you view that day's data. I...