I just loaded Splunk 6.2.3 and am forwarding event log events from my laptop running Windows 7. Everything looks OK except I cannot see any "EventLogDescription" datain Splunk. Was this a...
Hi, I'm new to Splunk.
I signed up for the Cloud trial.
When I first logged in I was presented with a "file upload" form to add datainto Splunk.
Ican't seem to find that form now (after a f...
...ourcetype=DataSource event="GRANTED"
| stats max(_time) AS lastUsed by Username
| rename Username AS samAccountName ]
So I get my lookup list of users, start the subsearch pull back a l...
...is-pic\PM\PMLog\PMLog.txt20111126
\\aaasvr\iis-pic\PM\PMLog\PMLog.txt20111128
\\aaasvr\iis-pic\PM\PMLog\PMLog20111128.txt
but in my source data, only one file (\\aaasvr\iis-pic\P...
I am trying to configure Splunk to ingest only application, system and security logs from my local machine. But Ican'tfind "Local event log collection" on my Splunk enterprise on my MacBook.&n...
...}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}
token.4.replacementType = timestamp
token.4.replacement = %Y-%m-%dT%H:%M:%S
Now the below were some of the events in my .csv file which I'd kept in samples d...
...The difference with these events compared to the ones with my new source type is that now Splunk tells me it found 133 events but Ican't see them, with the new source type Splunk doesn't find any e...
...ight source type, and for some reason Ican'tfind the datainput under "Datainputs" to edit it.
If I want to go to Add Data > Forward it tells me that "There are currently no forwarders c...