Hi,
I am trying to configure a lab environment but I am not seeing data in indexer. When I checked splunkd.log it says --
ERROR TcpOutputProc - Illegal format for config item 'uri'
ERROR N...
Hello! I have an environment with about 200 machines, all Windows Servers. All servers are sending TCP information through port 9997 directly to my Heavy Forwarder, all information is allocated i...
Hello everyone,
I have a lab in a Ubuntu VM. In this lab, I have the UF and the Splunk E. The forwarder monitors a folder that has a Catalina.out.bk file. The dataarrives at Splunk E but it a...
Hello, My team and I installed a new UF on one of our systems. we wanted it tosend the data from the system toa specific index we made for it. after we installed the UF it immediately s...
...onnected machine, it has a Universal Forwarder installed to it that sends directly to the CM and the data transmits successfully and all my data is indexed properly and extracts the fields as required....
I got an other question(s) regarding SplunkApp for Stream
I am playing around with the Netflow feature of Stream
I convinced our network guys tosend us some netflows.
Even that this is o...
I'm getting ready to finalize aSplunk install and roll it out for use... during my testing phase I added a bunch of datato my index that I don't need (eg, via syslog, WMI, legacy machines, etc). W...
...nd Display Current Environment *************
And start indexing events after that.
You could also use
HEADER_FIELD_LINE_NUMBER if your data
writes a consistent number of header
lines.
T...
Firstly I'm new tosplunkand a bit confused.
One question I would like answered first is can you use new indexes in the free version and have a Universal Forwarder senddatato it?
If so then c...
...ireeye HX is sending data via TCP in CEF format. On the CM: # cat etc/master-apps/_cluster/local/inputs.conf <snip> [tcp://:1234] index = fe_data sourcetype = hx_ce_syslog # ls etc/m...