Greetings! I'm still super new to splunk, so please be gentle :)
I am trying to extract a timestamp from CSV records.
A single CSV can contain N records. Each record has its own timestamp, but the ti...
...ynamically change and parse message logs and then parse with good sourcetype stanza and deliver to different index. depends on log type (eg. different OS, or network equipment, etc...)
I've implemented per-event sourcetypes assignment as described here: http://docs.splunk.com/Documentation/Splunk/5.0.3/Data/Advancedsourcetypeoverrides Basically it works. For events matching a R...
I've heard that using Splunk's default sourcetype detection is flexible, but can be hard on performance. What is the best way to define sourcetypes that keeps performance speedy?
I am dynamically extracting a sourctype using props.conf and tranform.conf file. But the extraction is not working as expected. The soucetype i am extracting is "e...
Both servers is CentOS 7
One with Splunk Enterprise 7.2.5
Splunk App for Infrastructure 1.2.3
Splunk Add-on for Infrastructure 1.2.3
one with Splunk Universal Forwarder 7.2.5
Error messa...
Hello,
System type: Linux
We have splunk running on our centralized syslog-ng server. We then have other servers forwarding syslog traffic to it. Those logs are then stored in their own f...
...nchqqsw108m\logs\anchqq-asa4-ncic\2014-05-22\daily-syslog.txt
\anchqqsw108m\logs\betast-asa4\2014-05-22\daily-syslog.txt
The sourcetype for the log monitor (\anchqqsw108m\logs) is set to automatic...