I followed the directions forconfiguring custom timestampsforeventswithmultipletimestamps but I am not getting the result I am looking for. Here is my props.conf in my $Splunk_home$/etc/s...
I've heard that using Splunk's default source type detection is flexible, but can be hard on performance. What is the best way to define source types that keeps performance speedy?
I have used the SEDCMD to take out an excess time that was added to the beginning of my logs so that the timestamp would use the second time (now the only time) showing in the event. The timestamp h...
...t;
<doc>
<num>1</num>
<num2>13</num2>
</doc>
</feed>
As you can see, the timestamp (lastUpdate=) is at the top of the document, which contains 2 events (i...
I have a log that looks like this:
2010/06/28 12:44:21 -
-ERROR(Version: 1.0 Buildguy from 2009-05-12 08.45.26) : 2010/06/28 12:44:21....
when I index it with the main index I get two events...
This isn't a question, rather just a place to drop a PDF I put together that I titled "Bare Bones Splunk" I've seen a lot of people try and get started with Splunk, but then get stuck r...
I'm seeing the error below under messages in my Splunk enterprise console:
Missing or malformed messages.conf stanza for TCPOUT:FORWARDING_BLOCKED_Indexer IP ADDress_default-autolb-group DC-Host N...
...0
From another Splunk Answers post "How to Configuretimestampsforeventswithmultipletimestamps" gkanapathy mentioned "it is very likely that the host that you see in the event (foo.bar.com) i...