The venerable old-skool Splunk forums are now closed. Feel free to search for old content here, but new posts are no longer supported.

Instead, please visit the thriving community at answers.splunk.com to ask and answer questions about your Splunk deployment and how to get the most out of it.

Forums: Posted by mdemansana

Topics 1–5 of 5

Topic Author Replies Latest Post
Windows 2008 Event Descriptions not displayed
In: SplunkAdministration (Not tagged)
Where is the fix for this? Is it with 4.0.8? I see this error on some machines.
CerielTjuh
Posts
11
29 months ago...
Newbie question on IIS reporting
In: SplunkReporting (Not tagged)
The documentation piece on the splunk website is a great way to start.
losromero
Posts
1
29 months ago...
Field Extraction from IIS W3C Extended Format
In: SplunkAdministration (Not tagged)
Use the same data in the inputs.conf, but I've modified the config on both the transforms.conf and the ...
Which props.conf, inputs.conf and transforms.conf file do you modify? The forwarder or the receiver?
otac0n
Posts
6
29 months ago...
Report Errors
In: SplunkReporting (Not tagged)
Which props and transforms file do you modify? The forwarder or the receiver?
anon1m0us
Posts
12
29 months ago...
Log Retention and Expiration
In: SplunkAdministration (Not tagged)
Spoke too soon! :) I did that and it seems to be able to allow for editing.
The indexes.conf config file is read only from the Windows installation. Is there anything that needs ...
I saw a post about the default value of splunk retaining log data of up to 90 days. If the retention ...
I saw a post about the default value of splunk retaining log data of up to 90 days. If the retention ...
Does Splunk allow for log expiration? If the retention period for logs are only for a year, how can ...
mdemansana
Posts
7
29 months ago...