...ssues as expected.
This is shown in the MC-->ndexing->Inputs-DataQuality->Timestamp Parsing issues.
All correct so far....
So I have created a props and transforms to send these g...
...ell using sourcetype=json_no_timestamp
As a default the timestamp for the indexed data is the current system time
Is there a way I can modify the date time for this particular input (I am using f...
Splunk is not indexing the data through the Scripted input.
The input is working for the on-premise servers, the datainput is through a universal forwarder. The same setup being configured, h...
Splunk ver : 6.6.6
OS : Linux 7
Universal Forwarder ver : 6.6.6
OS : Windows Server 2016
I configured below inputs.conf and sample.ps1 in the Universal Forwarder and Splunk indexed o...
Hey guys, I'm configuering indexer cluster, so I'm gonna have like this: sh1+sh2 ix1+ix2+ix3_master (indexer cluster) 1. How should I configure DB input from our Oracle DB to the indexer c...
Hi everyone,
I have some problem with datainput on UDP port
I send from a log collector syslog messages.
These are bein received by the splunk host (tcpdump capture) but not indexed.
Data...
I have a UF running at version 6.0.4. I have configured an inputs.conf value to route to a different indexer. The UF isn't honoring the statements in the inputs.conf and outputs.conf. This should w...
...his is what I currently have for the Props.conf and Transforms.conf on the Indexer.
Props.conf
[source::<same source as used in the inputs.conf file on the Universal Forwarder>]
TRANSFORMS-v...
...We are looking for a recommendation for the best practice on how to deploy these input scripts on our indexing cluster so that they will be fault tolerant like all of our other data ingested into t...