Hello 🙂 I have splunk getting data from a folder everyday. Recently the files changed the name of the fields. Here is a sample there are 44 fields in total, Old New
Number number
Corr...
...utputs.conf in Heavy Forwarder. outputs.conf [indexAndForward]
index = true In fact the indexing is false on this node and this HF forward data to my indexer c...
The advisory (https://www.splunk.com/en_us/product-security/announcements/svd-2022-0502.html) talks about Splunk Enterprise, but makes no mention of the Universal forwarder. Since UF has many of the...
Hello All, I'm having an issue where I am unable to create new correlation searches. I get the following error: There was an error saving the correlation search: In handler 'savedsearch': ...
Hello, We recently installed Splunk, we thought we had a free license, however we got a notice that we have exceeded the quota and the license has been blocked. We have changed the license group to ...
I believe i'm on the most current version, I'm not clear on why I am getting these messages.. When I click on the links, it takes me to the general products screen of Splunk. When I clear the message...
Hello Everyone, I have a question. I have events like: Mon Mar 19 20:16:03 2018 Info: Delayed: DCID 8414309 MID 19410908 From: <WeiZhang@example.com> To: <mcintosh@buttercupgames.com> R...
hello splunkers,
I have build server using shuttle with VM ware Hyper-v
i have splunk downloaded and installed on servers that i have created, i am able to use the ip addres on the splunk h...
Hi there, When reviewing Splunk events, some events display as below, it splits following text into two events; the second event has no datetime at the beginning, and the log is from log4net w...