The venerable old-skool Splunk forums are now closed. Feel free to search for old content here, but new posts are no longer supported.

Instead, please visit the thriving community at answers.splunk.com to ask and answer questions about your Splunk deployment and how to get the most out of it.

Forums: Posted by kevintelford

Topics 1–5 of 5

Topic Author Replies Latest Post
incrementing sourcetype name
In: SplunkAdministration (Not tagged)
We're currently on 4.1 and this has only seemed to happen since we've upgraded, and only on new data ...
kevintelford
Posts
1
25 months ago...
Indexing and parsing tool
In: SplunkRequest (Not tagged)
I'd be nice to be able to point Splunk at a test file and see how your regexs and whatnot will effect ...
kevintelford
Posts
1
25 months ago...
Extracting information from a search
In: SplunkSearchAndAlert (Not tagged)
If this is something you'll be looking for often, or at least once and a while, you should setup a search-time ...
steveirogers
Posts
1
26 months ago...
Host Substitution
In: SplunkAdministration (Not tagged)
If you're doing this at index time you need WRITE_META = true in your transforms.conf. http://www...
kholleran
Posts
4
26 months ago...
Data not being forwarded in real time
In: SplunkAdministration (Not tagged)
Depending on the version of Splunk you're running, you may be getting the 2010 timestamp issue they ...
I'd start by establishing if data is making it to your indexer. Try running a search on the internal ...
tsingara
Posts
4
26 months ago...