Hello, community, I wanted to ask a fundamental question regarding specific logs collection. The question is: Do we really pull logs from the AD by sticking an agent on that AD DC machine/s? I h...
...| collect index=sec_apps_summary source="savedSearch_1d" And earliest , latest setting as -1@d and @d . There is another SEARCH-2, that invokes the 'saved search' and the SPL starts l...
Intermittent text file data collection is not possible.
Initially, it is a collection of csv file data.
After that, if you change only a few characters in the csv, you cannot collect them i...
Hello, 1) What is the difference between using "| summaryindex" and "| collect"? Thank you for your help. Summaryindex is generated by a scheduled report. I clicked "view recent" and the f...
Is it possible to use collect command to collect data from one index and move it to another, where destiation index is not a summary index ?
index=whatever host=whatever source=whatever w...
which mode does the splunk forwarder support ? If push or pull mode is all supported, we want to know how to configure the different mode,and the disad...
Hi Splunkers,
for our customer we collect log from Windows systems. The main configuration details are:
Logs go from DCs to a dedicated HF and then to Splunk Cloud, so the flow is: DCs -> H...
Hi Splunkers, for a customer we are preforming a migration in Windows Logs collection: as suggested by some of you in another topic, we are passing from WMI method to UF one (and it is very, very, v...
Did i mess something or just compeletly don't understand what collect does. Below is may saved search and conf file, it returns results, it saved as report, it is scheduled seach, and it runs. h...
...inute. How do I ensure the collector won't miss log entries or duplicate log entries in this scenario? Or are we always at risk of the collector missing the last few log entries that push the&n...