Activity Feed
- Karma Re: How to index only one day of data from a batch output? for twinspop. 06-05-2020 12:48 AM
- Karma Re: Search formatting in Splunk 6.5.0 for easier readability for lquinn. 06-05-2020 12:48 AM
- Karma Why does Splunk think my file is binary for a212830. 06-05-2020 12:48 AM
- Karma Why am I getting these failed bucket replication errors on each indexer in a cluster? for klutzen. 06-05-2020 12:48 AM
- Got Karma for How to set a single value result to show the Total and have a sparkline showing the trending average underneath?. 06-05-2020 12:48 AM
- Got Karma for How to set a single value result to show the Total and have a sparkline showing the trending average underneath?. 06-05-2020 12:48 AM
- Got Karma for How to set a single value result to show the Total and have a sparkline showing the trending average underneath?. 06-05-2020 12:48 AM
- Karma Why does the startup.handoff for searches from our Splunk App for Enterprise Security search head seem to take a long time? for madcitygeek. 06-05-2020 12:47 AM
- Karma Can somone share a simple XML tag to change the Pie Chart label font size? for kallisrayar1986. 06-05-2020 12:47 AM
- Karma Re: listing properties for a pre-trained sourcetype for martin_mueller. 06-05-2020 12:47 AM
- Karma Re: How to configure Chrome as a search engine for Splunk queries? for MuS. 06-05-2020 12:47 AM
- Karma Re: Fields extraction from access log for lguinn2. 06-05-2020 12:47 AM
- Karma Export to PDF Unable to Save for john_howley. 06-05-2020 12:47 AM
- Got Karma for Re: Why are we getting "error getting attributes of path "C:\pagefile.sys":..." on one set of Splunk forwarders?. 06-05-2020 12:47 AM
- Karma Re: List of default working extractions in Splunk like "| extract access-extractions" for richgalloway. 06-05-2020 12:46 AM
- Karma Re: File growth rate must be higher than indexing or forwarding rate. for dmaislin_splunk. 06-05-2020 12:46 AM
- Karma Re: [AIX] Universal Forwarder requires read access on `/etc/inittab` or else daemon won't start for dvanzuijlekom. 06-05-2020 12:46 AM
- Karma Re: tarAndChecksum error for deployed app inputs.conf for Wallen. 06-05-2020 12:46 AM
- Karma Re: How can I set a dynamic default value in a dropdown (Simple XML) for nfilippi_splunk. 06-05-2020 12:46 AM
- Karma Re: Is there a way to backup/export a dashboard for NK_1. 06-05-2020 12:46 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 | |||
0 | |||
0 | |||
3 | |||
0 | |||
0 |
05-08-2017
01:27 PM
Can I use the same HEC token on all HF's which are behind a VIP and set up clients to send data to VIP ip?
The purpose is to keep HF's conf the same and share the load.
Is it a good idea?
... View more
- Tags:
- heavy-forwarder
02-10-2017
08:01 AM
what limitations did you have please?
thanks.
... View more
07-15-2016
08:07 AM
Thanks twinspop. it turns out a file permission problem on the servers and your setting works.
... View more
07-15-2016
06:53 AM
I have this inputs.conf
[ServerLogs]
SHOULD_LINEMERGE = true
TRUNCATE = 0
BREAK_ONLY_BEFORE = ^\d{6}\s+\d{2}\:\d{2}\:\d{2}\:\d{3}\s+
TIME_PREFIX = ^
MAX_TIMESTAMP_LOOKAHEAD = 20
TIME_FORMAT =%m%d%y %H:%M:%S:%3N
BREAK_ONLY_BEFORE_DATE = true
and piece of my log looks like:
<imagePath>C:\Fiserv\TCAP\bin\..\data\images\20160714222778400413_20160714141254232.img</imagePath>
</imageObject>
<itemUserFields />
<cpcsData />
071216 09:36:03:364 4524/6.4.2.10/2 INFO CCaptureApiServerApp::InitInstance(): before requestProcessor.DoModal()
Second piece of log was recognized correctly with property time format. however for the first piece, the line was also broken before, and a time was recognized from "20160714141254232", which I am confused that that's not the time format I defined.
Anyone can shed some light here?
... View more
07-14-2016
11:31 AM
You are absolutely right!!
just tested out and it works!
It would only keep the first copy Splunk sees as the source, but it doesn't matter in my situation!
Thanks a lot TWINSPOP!!
... View more
07-14-2016
11:09 AM
what value would you suggest to use?
without crcSalt, splunk will ignore the file.log 2nd time it sees it because they have the same CRC value.
From http://docs.splunk.com/Documentation/Splunk/6.4.1/Admin/Inputsconf
(Splunk only performs CRC checks against, by default, the first 256 bytes
a file. This behavior prevents Splunk from indexing the same file twice,
even though you may have renamed it -- as, for example, with rolling log
files. However, because the CRC is based on only the first few lines of
the file, it is possible for legitimately different files to have matching
CRCs, particularly if they have identical headers.)
... View more
07-14-2016
10:59 AM
it involves 4 parties to do it....believe me I am trying....
... View more
07-14-2016
10:58 AM
i understand what you meant, but each day batch script will dump a new file to the /data folder. That file will have the history data and new data.
... View more
07-14-2016
10:48 AM
how so please?
/data/20160711/file.log <---a
with events:
day1.0
day1.1
/data/20160712/file.log <---b
with events:
day1.0
day1.1
day2.0
day2.1
day2.2
/data/20160713/file.log <---c
with events:
day1.0
day1.1
day2.0
day2.1
day2.2
day3.0
day3.1
My goal is to only index
day1.0
day1.1
day2.0
day2.1
day2.2
day3.0
day3.1
but what am I getting on the 3rd is:
day1.0
day1.0
day1.0
day1.1
day1.1
day1.1
day2.0
day2.0
day2.1
day2.1
day2.2
day3.0
day3.1
... View more
07-14-2016
10:17 AM
For now it's very simple
[monitor:///data/.../file.log]
index = myIndex
sourcetype = myType
crcSalt = [SOURCE]
... View more
07-14-2016
10:15 AM
If we could, we would...
right now we can only rely on this batch process to pull the data from 1000+ workstations to a central location.
... View more
07-14-2016
10:07 AM
I have a situation to index batch output into Splunk.
The output looks like:
/data/20160711/file.log <---a
/data/20160712/file.log <---b
/data/20160713/file.log <---c
Every day, the batch job copies the file.log into this subfolder under /data. But file.log is not rotated by date, but by size, which means if not rotated, file.log a,b,c could have duplicate data.
Tight now I have a forwarder monitoring everything under /data, but it caused quite some duplication.
What's the best way to just index the data for the day from each file?
... View more
03-31-2016
12:55 PM
What I hope to achieve is to have the 68 represents the running TOTAL, -135 is the trend from an hour ago and the sparkline shows the 15 minutes average.
Right now I can only show the last 15 mins' avg where the [68] is.
thanks.
... View more
03-30-2016
12:23 PM
3 Karma
To my understanding, single value uses the first value of the result table.
However, how do I build the search for the single value panel to show the total and sparkline underneath to show average?
Also, how do I change the trend indicator to compare current total and total an hour ago?
... View more
03-29-2016
07:39 PM
I have the same problem!
the font size is way too big than needed.
... View more
03-15-2016
01:07 PM
but what if we want to change the font size for the pie label?
... View more
08-07-2015
05:45 AM
say with in 5 mins we have A100, B 1000, C 50. right now plain vanilla timechart with bar will order by legend name. Instead of the order of A B C, we would like to see an order of BAC from top to bottom as B has the largest value. Hope this explains.
... View more
08-07-2015
05:43 AM
you got a point! it's a customer request and I couldn't figure out a solution.
is there a way to do with just regular chart?
... View more
08-06-2015
10:04 AM
1 Karma
Just to post the answer from the support:
when we define input stanza using wildcard like [monitor://C:\Program Files*....] in this case splunk will traverse one level up and start monitoring from c:\ and hit the error you are seeing.
So in you case simple solution will be to change the "monitor://C:\Program Files*" to either
[monitor://C:\Program Files....
or
[monitor://C:\Program Files (x86)....
... View more
07-17-2015
12:30 PM
I have same problem....
... View more
07-06-2015
11:09 AM
I did a "splunk list monitor" but pagefile.sys is not in the list.
We use deployment server to push forwarder settings and I double checked that file or its parentdirectory(c:) is not in our inputs.conf.
... View more
07-06-2015
10:53 AM
In one set of our Splunkforwarders, we keep getting the following error msg:
FilesystemChangeWatcher - error getting attributes of path "C:\pagefile.sys": The process cannot access the file because it is being used by another process.
It only happens to this set of servers and every one of them.
What could be the possible reason for it?
thanks.
... View more