How can I tell where data is coming from? I have inherited an old Splunk 5.0.1 Enterprise Infrastructure. I can see data on the Splunk head for a specific (IP) server, however, this data is coming into _main. I got on the Windows box where this data is coming from and I could not see a universal forwarder or syslog implementation despite much searching. I do not know how the data is coming into Splunk, which is a problem since I need the data to go into a different index. This leaves me asking, how is the data coming in? Is there a way to trace events all the way back to the origination point AND know what the path that the data took? I there a way to know what process originated the data on the machine?
... View more
I contacted the developer and he pointed out that it uses syslog, I have no idea whay I had SNMP stuk in my head. It works quite well now.
... View more
Yes, I read the one sentence of documentation, and assume I needed to enable SNMP, which I did using Airport Utility 5.6.1 on my MAC Mini. On my OPenSUSE machine which runs Splunk 6.3 Enterprise, I added the Airport APP. No data in Splunk from my Airport Extreme, is there anything else that need to be done. With so little documentation I wonder if I am missing something.
... View more
I am running Splunk 6.3 Enterprise (Free) running on OpenSUSE 13.2 at home attempting to use the Airport App. and no far I have not seen any data. Any ideas hints etc...?
Thank!
... View more