Hi,
I am trying to configure a lab environment but I am not seeing data in indexer. When I checked splunkd.log it says --
ERROR TcpOutputProc - Illegal format for config item 'uri'
ERROR N...
Hello everyone,
I have a lab in a Ubuntu VM. In this lab, I have the UF and the Splunk E. The forwarder monitors a folder that has a Catalina.out.bk file. The dataarrives at Splunk E but it a...
I had a little test environment set up to test forwarding toa test indexer and it worked fine. Now, I altered the files tosenddatato our production indexers, and although the forwarder appears to...
Hello! I have an environment with about 200 machines, all Windows Servers. All servers are sending TCP information through port 9997 directly to my Heavy Forwarder, all information is allocated i...
Hello, My team and I installed a new UF on one of our systems. we wanted it tosend the data from the system toa specific index we made for it. after we installed the UF it immediately s...
...nd Display Current Environment *************
And start indexing events after that.
You could also use
HEADER_FIELD_LINE_NUMBER if your data
writes a consistent number of header
lines.
T...
Firstly I'm new tosplunkand a bit confused.
One question I would like answered first is can you use new indexes in the free version and have a Universal Forwarder senddatato it?
If so then c...
I'm getting ready to finalize aSplunk install and roll it out for use... during my testing phase I added a bunch of datato my index that I don't need (eg, via syslog, WMI, legacy machines, etc). W...
... I want to ensure when my UF starts, it should send the datato "logs_data" index by default (assuming this index is present in the SplunkIndexer) I tried overriding the default i...
...Ms running in the cloud under a different cloud account.
Each Splunkaccount that corresponds toa cloud account will have read access to only 2 indexes:
1) an indexfor their non "OS" data
2...