The venerable old-skool Splunk forums are now closed. Feel free to search for old content here, but new posts are no longer supported.

Instead, please visit the thriving community at answers.splunk.com to ask and answer questions about your Splunk deployment and how to get the most out of it.

Forums: Posted by mvanaswegen

Topics 1–19 of 19

Topic Author Replies Latest Post
Dynamic Meta Data Assignment
In: SplunkAdministration (Not tagged)
Thank Alex and Gerald! I think this proves that it's possible to implement my scheme. Here's a ...
Hi Alex Almost, event 3 is still not complete, but to build a general purpose regex for this case ...
Hi Gerald We're a bit closer, event 3 has some collateral damage. splunk search "*" 20/02/2010 ...
The extraction works, the cleaning transform doesn't.
Hi Guys "Wait, so you just want a field to appear as meta data, but you *don't* want it in the raw ...
Hi All From my post on http://bit.ly/97CEi3 Splunk is infinitely configurable when it comes to ...
mvanaswegen
Posts
9
24 months ago...
Monitoring SAP?
In: SplunkGeneral (Not tagged)
gkanapathy, you are welcome to email me if you want details.
gkanapathy, I have built it. I collect all dev traces, logs, config data, enviroment info, etc. Alex ...
mitchs
Posts
6
26 months ago...
Mutiplexing Feeds
In: SplunkAdministration (Not tagged)
Hi Guys I have a question. I previously solved a event mutiplexing problem using the Splunk header, ...
mvanaswegen
Posts
27 months ago...
High CPU(100%) , Load Average(10.5), Top process Splund
In: SplunkAdministration (Not tagged)
I've also had a similar problem on my Ubuntu Server 9.04 (64bit) Dual Core with Splunk version 4.0.3. ...
jean_tomaz
Posts
4
29 months ago...
ExecProcessor
In: SplunkApplications (Not tagged)
Alex just spotted this in the dox. http://www.splunk.com/base/Documentation/latest/Admin/Setupcustom%28scripted%29inputs Caution: ...
Alex I've actually built binaries using cx_freeze. The exec processor calls a frozen binary, it looks ...
Hi I've noticed that the ExecProcessor is complaining about a shared library that ships with Splunk. ...
mvanaswegen
Posts
5
29 months ago...
App Defaults
In: SplunkAdministration (Not tagged)
Thanks Emma, I really think there should be an easier way to do this via the UI.
Hi Is there a way to configure what app is launched by default? Marinus
mvanaswegen
Posts
4
31 months ago...
SAP NetWeaver
In: SplunkApplications (Not tagged)
Hi Guys I've built a SAP NetWeaver App, if you are interested in beta testing drop me a mail. ...
mvanaswegen
Posts
35 months ago...
Surgical Removal from Index
In: SplunkAdministration (Not tagged)
Hi Is there a way to remove events and index entries for a particular search term. It appears that ...
mvanaswegen
Posts
1
36 months ago...
3.4.5 upgrade - causing server to hang
In: SplunkAdministration (Not tagged)
I've noticed that under Windows 3.4.5 is also misbehaving. In the past I could just do a quick .. splunk ...
jmcgranahan
Posts
5
38 months ago...
Mangling
In: SplunkSearchAndAlert (Not tagged)
Hi Guys I've run into a big of a snag. I love the fact that I can extract fields with rex and report ...
mvanaswegen
Posts
1
38 months ago...
Sources
In: SplunkAdministration (Not tagged)
Hi You hit the nail on the head! Now I just have to wait for 4.0 to ship. Thanks Marinus
Hi Guys I'm indexing a couple of hundred sources. It's becomming really hard to manage them via the ...
mvanaswegen
Posts
2
38 months ago...
Just plain source type
In: SplunkApplications (Not tagged)
Thanks Yancy and Alex. I did notice that my config file contains about two thoudand off key vale pairs ...
Hi Alex It works, just one question if I have a config file with two thousands odd lines it splits ...
Hi I'm producing a simple text file which I'd like Splunk to index. Splunk keeps breaking the lines ...
mvanaswegen
Posts
4
38 months ago...
Complex extraction
In: SplunkApplications (Not tagged)
Hi perhaps i need to explain the use case since i think theres an easier way to get at the juicy meta ...
Hi I'm trying to extract the appropriate meta data from the name of a file without much success. file ...
mvanaswegen
Posts
2
39 months ago...
Extracting the Host from a filename
In: SplunkApplications (Not tagged)
Thanks, got it working. I just planted a * in the source stanza to handle all cases. :) Just ...
Hi Ariatz Thanks, works like a charm. If I want to set the source key based on a file regex could ...
HI I'm trying to index a bunch of file where the system name is in the filename i.e. nemo_server.log, ...
mvanaswegen
Posts
6
40 months ago...
Mainframe RACF
In: SplunkGeneral (Not tagged)
Hi I've done some work with CA/TSS. You will most probably have to write a report to extract what ...
gmortier
Posts
1
40 months ago...
Series problems
In: SplunkReporting (Not tagged)
Excellent! Thank kbains
Using rex I extracted all 5 to CMD_1, 2 ... 5. They values appear as normal percentages, however the ...
Hi I poll the source very couple of minutes and I get the following result. Row 0=TSS9590I Init(001173424) ...
Hi I've extracted the following fields Cmd 01 - 05. They contain percentages i.e. 006.94%, 014.09%, ...
mvanaswegen
Posts
7
40 months ago...
Packaged Scripted Inputs
In: SplunkApplications (Not tagged)
I resolved the issue. I just renamed the app dir and I didn't change the ./bin to ../bin. For some ...
/splunk/etc/apps/scripts$ ls -lR .: total 12 drwxr-xr-x 2 m m 4096 2008-10-15 22:30 bin drwxr-xr-x ...
12342ccddd
Posts
4
41 months ago...
Post Processing (skipping)
In: SplunkApplications (Not tagged)
Hi I'm tailing an input that needs a little post processing (deletion and concatenation). Here's ...
mvanaswegen
Posts
1
41 months ago...
Scripted Inputs
In: SplunkApplications (Not tagged)
Hi I've got a bunch of python scripted inputs. Does Splunk index any useful information regarding ...
mvanaswegen
Posts
1
41 months ago...