The venerable old-skool Splunk forums are now closed. Feel free to search for old content here, but new posts are no longer supported.

Instead, please visit the thriving community at answers.splunk.com to ask and answer questions about your Splunk deployment and how to get the most out of it.

Forums: Posted by seanlon11

Topics 1–5 of 5

Topic Author Replies Latest Post
Using Apache HTTP server to redirect port 80 to Splunk's port
In: SplunkAdministration (Not tagged)
Thanks for the reply rotten. I have added your suggestion in the VirtualHost area of my httpd.conf, ...
I am new to Apache HTTP, which complicates things, but so far, I have found a way to point the "DocumentRoot" ...
seanlon11
Posts
5
25 months ago...
duplicate data being indexed from forwarders
In: SplunkAdministration (Not tagged)
I have excluded all whitelist/blacklists. I have setup my Data Inputs here: <splunk>/etc/apps/search/local/inputs.conf [monitor:///opt/IBM/WebSphere/AppServer/profiles/AppServer/logs/MyCompany_Level_1_WAS01/SystemOut.log] disabled ...
When I do a search for a username that should only show up once (b/c there is only 1 entry in my SystemOut.log ...
seanlon11
Posts
4
28 months ago...
forward data to an IP address
In: SplunkAdministration (Not tagged)
Ok, I have fixed this issue. I found where “portal03” was still being referenced instead of the ...
Ok, so it appears that I can telnet into "portal03". wasadmin@hhwas01:~> telnet 172.29.61.12 9997 Trying ...
I have successfully setup multiple forwarders to our indexing server "portal03". However, I am now ...
seanlon11
Posts
5
28 months ago...
filter out files from forwarder via _blacklist
In: SplunkAdministration (Not tagged)
I have tried a few variations, but so far it appears that it is not recursive. So I am obviously doing ...
Formatting messed up my dir. structure, so here is a different view: /users/ /users/eric /user...
The formatting messed up my dir structure, so here is a different view: /users/ /users/eric /u...
Along this same topic, I am curious if sub-directories are looked at as well for a given stanza. My ...
Thanks for the quick reply araitz!
Sweet. Mr. Wilde from Splunk support helped me out: simply put the data to be filtered out on the ...
I have a forwarder setup (aka was03), and a Splunk indexer (aka splunk00). The forwarder is sending ...
seanlon11
Posts
8
29 months ago...
filter out files from forwarder via _blacklist
In: SplunkPreview (Not tagged)
Posted in the wrong spot. Below is the place to reply: http://www.splunk.com/support/forum:Splu...
I have a forwarder setup (aka was03), and a Splunk indexer (aka splunk00). The forwarder is sending ...
seanlon11
Posts
1
29 months ago...