...im of those Splunk HF is to offload the Splunk Indexer on parsing Pipeline, Merging Pipelineand Typing Pipeline. Due to that thedata coming from Splunk HF are already "processed" and our I...
I was under the impression I could define sourcetypes in props.conf on the forwarder, which would then send that dataandthe sourcetype information to the indexers. It looks like it does this, at l...
...group=pipelinedata does not appear in the results on the left however it does on thedata on the right when you change
group_is_it_searchable=no
to
group_is_it_searchable=*no
I will put the...
Splunk Universal Forwader constantly crashes with "Crashing thread: indexerPipe".
splunkd.log shows:
WARN IndexerService - Indexer was started dirty: splunkd startup may take longer than usual...
Hi guys, i am having an issue with the xml script in the last line but i cant seem to figure out how to make it valid as i have.
Have tried double quotes but does not work.
data-o...
...equest the folks to copy the transforms and props files to right folder on splunk main server (/splunk\etc\apps\appnamePOC\local).
can I place these files on my splunkuniversalforwarder machines r...
Hi friends! Im doing a search like index=_internal From a custom app, even if Im the admin user. I have a cluster Splunk architecture and still I obtain messages like this Search r...