...ave forwarding andmonitoring all set up correctly.
My issue is that once I start creating additional files in that directory (which contain JSON-formatted trace information), they don't show up on t...
I must be doing something wrong. Splunk is seeing and indexing the first log file it finds and nothing else after within the same folder and nothing else after in the other folders. Any advice? T...
...lternatives to do this? I've tried using data input andmonitorfilesanddirectories via splunkweb but it doesnt seem to be informative.If there is an image file,then the event will show up with g...
...nstalled Splunk on a local machine and created a local folder to drop the files into (we have 4 servers for an application, each creating 1 log per day).
I've setup a data input via web interface (a...
I've installed Splunk (4.1.5(85165) on windows) and have uploaded some logs without any issues.
I now want to monitor a linux server, but I'm having problems adding the datasource and always get t...
...se the same username and password can not login the web interface. If I remove $SPLUNK_HOME/etc/passwd to "passwd.bak" and restart splunk, when I try to login with "admin" it will say "No users exist....
Hi,
as you can see I'm new to splunkand I need some tips to find a solution for my problem.
I have to monitor different directory's on our windows file server for file access/modification/d...
...hat port when I checked with netstat and via the resource monitor. I tried rebooting to no avail. I found the following posts:
https://answers.splunk.com/answers/545000/slow-splunkweb-startup-c...
Hello!
This most likely is operator error, but not sure; don't seem to be able to do this in one GUI effort.
Using: Settings-->Data Inputs-->Add new (Files & directories)
If I s...
...asically anything that is a current *.log file.
What I want to do is only index the "web" servers and only the uncompressed *.log files. It should ignore the app server directories.
I setup an i...