The venerable old-skool Splunk forums are now closed. Feel free to search for old content here, but new posts are no longer supported.

Instead, please visit the thriving community at answers.splunk.com to ask and answer questions about your Splunk deployment and how to get the most out of it.

Forums: Posted by msallman

Topics 1–3 of 3

Topic Author Replies Latest Post
Windows App & WMI Sourcetype
In: SplunkAdministration (Not tagged)
Working on getting WMI input working (on 4.0 still). We seem to be having trouble getting the sourcetype ...
msallman
Posts
22 months ago...
Mysterious IIS-2 sourcetype
In: SplunkGeneral (Not tagged)
I do have it in inputs.conf: [monitor://\\iis_server\LogFiles\W3SVC1] disabled = 0 host = iis_server sourcetype ...
Since upgrading to 4.0.9, Splunk seems to have decided that I need an IIS-2 sourcetype (created in /etc/apps/learned/local/props.conf ...
msallman
Posts
5
24 months ago...
Splunk bug with backslash and quotes - escape character \
In: SplunkGeneral (Not tagged)
I just upgaded to 4.0.10 and that seems to have fixed the problems I was having with the escaping & ...
Ok, thanks.
Are those issues accessible anywhere on the website? It seems from the descriptions in the release ...
Is this one of the issues (SPL-26944, SPL-28136, SPL-28640) that were fixed in release 4.0.9?
scarolan108
Posts
14
24 months ago...