<?xml version="1.0" ?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
	<channel>
		<title>Splunk Base : SplunkAdministration</title>
		<link>http://www.splunk.com/support/forum:SplunkAdministration</link>
		<description>Discussion on topics around administering Splunk. </description>
		<pubDate>Mon, 13 Feb 2012 14:32:02 PST</pubDate>
		<lastBuildDate>Mon, 13 Feb 2012 14:32:02 PST</lastBuildDate>
		<language>en-us</language>
		<copyright>http://creativecommons.org/licenses/by-nc-nd/2.5/</copyright>
		<item>
			<title>Recovering from catastrophic crash</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4505/14646</link>
			<description>&lt;p&gt;So we had a catastrophic crash on our Splunk server and had to restore from back up, but after the restore the Splunkd daemon kept crashing. If we do a new install it works fine, but then we can't access our 23gig of DB's with very important data. Is there a way to import our old DB's so that the data can be recovered? This is on a windows system.&lt;/p&gt;

&lt;p&gt;Thanks in advance!&lt;/p&gt;

</description>
			<pubDate>Thu, 24 Mar 2011 15:01:44 PDT</pubDate>
			<author>svisionguy</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4505/14646</guid>
		</item>
		<item>
			<title>Splunk With Cisco ACS</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4470/14636</link>
			<description>&lt;p&gt;Any updates on this?&lt;/p&gt;

</description>
			<pubDate>Mon, 21 Mar 2011 10:07:51 PDT</pubDate>
			<author>seefor</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4470/14636</guid>
		</item>
		<item>
			<title>Intermediate Forwarder Cooked Event Data Filter</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4503/14635</link>
			<description>&lt;p&gt;Hi,&lt;/p&gt;

&lt;p&gt;I have the regex transforms working. We changed one light forwarder to tcpoutput raw and it appears good.&lt;/p&gt;

&lt;p&gt;So, can we say that regex transforms AKA filters will not happen on cooked event data as opposed to raw TCP input data?&lt;/p&gt;

&lt;p&gt;Another problem though is that raw TCP input data is not processed through the intermediate forwarder. Can this be done? TCP raw input into the parsing queue with applied regex transforms and cooked TCP event data output?&lt;/p&gt;

&lt;p&gt;Like so: raw TCP input &amp;gt; parsing queue &amp;gt; props|transforms &amp;gt; cooked TCP output... can someone please identify the exact path taken through the data pipeline including which segments and processors are used?&lt;/p&gt;

&lt;p&gt;Thanks.&lt;/p&gt;

</description>
			<pubDate>Mon, 21 Mar 2011 05:27:56 PDT</pubDate>
			<author>ephemeric</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4503/14635</guid>
		</item>
		<item>
			<title>Intermediate Forwarder Cooked Event Data Filter</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4503/14634</link>
			<description>&lt;p&gt;Hi,&lt;/p&gt;

&lt;p&gt;We have a 4.1.6 light forwarder sending to a 4.1.7 intermediate forwarder to a 4.1.7 indexer in default cooked format.&lt;/p&gt;

&lt;p&gt;Try as I might the below filter will not work on the intermediate forwarder.&lt;br /&gt;
The default SOURCE_KEY = _raw concerns me.&lt;br /&gt;
Will the filter be matched on cooked event data?&lt;/p&gt;

&lt;p&gt;Thanks.&lt;/p&gt;

&lt;p&gt;props.conf&lt;br /&gt;
[source::&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/WinEventLog&quot;&gt;WinEventLog&lt;/a&gt;:Security]&lt;br /&gt;
TRANSFORMS-null = setnull&lt;/p&gt;

&lt;p&gt;transforms.conf&lt;br /&gt;
[setnull]&lt;br /&gt;
REGEX = &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/EventCode&quot;&gt;EventCode&lt;/a&gt;=565&lt;br /&gt;
#REGEX = (?m)^&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/EventCode&quot;&gt;EventCode&lt;/a&gt;=(565|566|538)\b&lt;br /&gt;
DEST_KEY = queue&lt;br /&gt;
FORMAT = nullQueue&lt;/p&gt;

</description>
			<pubDate>Thu, 17 Mar 2011 07:18:31 PDT</pubDate>
			<author>ephemeric</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4503/14634</guid>
		</item>
		<item>
			<title>Default password fails</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4497/14632</link>
			<description>&lt;p&gt;these forums are deprecated. please post further questions over at answers.splunk.com. this seems like a support case, though--file a case via the support portal.&lt;/p&gt;

</description>
			<pubDate>Wed, 16 Mar 2011 12:00:35 PDT</pubDate>
			<author>rachel</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4497/14632</guid>
		</item>
		<item>
			<title>error when triggering script by a saved search</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4447/14631</link>
			<description>&lt;p&gt;Hey,&lt;/p&gt;

&lt;p&gt;I am getting pretty much the same error when I try to run a Perl script as well.&lt;/p&gt;

&lt;p&gt;Have you figured this out?&lt;/p&gt;

&lt;p&gt;Thanks.&lt;/p&gt;

</description>
			<pubDate>Wed, 16 Mar 2011 09:52:37 PDT</pubDate>
			<author>Greg_LeBlanc</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4447/14631</guid>
		</item>
		<item>
			<title>Remove host data</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4422/14629</link>
			<description>&lt;p&gt;Bump&lt;/p&gt;

</description>
			<pubDate>Tue, 15 Mar 2011 15:15:42 PDT</pubDate>
			<author>mntbighker</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4422/14629</guid>
		</item>
		<item>
			<title>Default password fails</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4497/14628</link>
			<description>&lt;p&gt;So far still not a peep from Splunk team. I deleted 4.1.7 entirely and installed 4.2 with the same result. No way to log into the web interface.&lt;/p&gt;

</description>
			<pubDate>Tue, 15 Mar 2011 15:12:33 PDT</pubDate>
			<author>mntbighker</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4497/14628</guid>
		</item>
		<item>
			<title>Windows 2008 Event Descriptions not displayed</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/3418/14626</link>
			<description>&lt;p&gt;I'm seeing a slightly different phenomenon in version 4.1.7, build 95063.&lt;/p&gt;

&lt;p&gt;I get a Message=NULL for my events, even when I look at the source.   Is this possibly related?&lt;/p&gt;

&lt;p&gt;I'm even more confused because I had this same configuration working in a lab.&lt;/p&gt;

&lt;p&gt;20110310224043.000000&lt;br /&gt;
Category=14081&lt;br /&gt;
&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/CategoryString&quot;&gt;CategoryString&lt;/a&gt;=NULL&lt;br /&gt;
&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/ComputerName&quot;&gt;ComputerName&lt;/a&gt;=zzzzzzzzz&lt;br /&gt;
&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/EventCode&quot;&gt;EventCode&lt;/a&gt;=5136&lt;br /&gt;
&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/EventIdentifier&quot;&gt;EventIdentifier&lt;/a&gt;=5136&lt;br /&gt;
&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/EventType&quot;&gt;EventType&lt;/a&gt;=4&lt;br /&gt;
Logfile=Security&lt;br /&gt;
&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/RecordNumber&quot;&gt;RecordNumber&lt;/a&gt;=349210678&lt;br /&gt;
&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/SourceName&quot;&gt;SourceName&lt;/a&gt;=Microsoft-Windows-Security-Auditing&lt;br /&gt;
&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TimeGenerated&quot;&gt;TimeGenerated&lt;/a&gt;=20110310224043.198864-000&lt;br /&gt;
&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TimeWritten&quot;&gt;TimeWritten&lt;/a&gt;=20110310224043.198864-000&lt;br /&gt;
Type=Audit Success&lt;br /&gt;
User=NULL&lt;br /&gt;
wmi_type=&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/WinEventLog&quot;&gt;WinEventLog&lt;/a&gt;:Security&lt;br /&gt;
Message=NULL&lt;/p&gt;

</description>
			<pubDate>Thu, 10 Mar 2011 14:47:04 PST</pubDate>
			<author>hughkelley</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/3418/14626</guid>
		</item>
		<item>
			<title>Default password fails</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4497/14625</link>
			<description>&lt;p&gt;I have deleted the whole thing and cleaned up all remnants I could find. After reinstalling I have the exact same issue. This one Linux system only? I submitted a ticket on 2/28 and so far no sign of any activity.&lt;/p&gt;

</description>
			<pubDate>Mon, 07 Mar 2011 18:15:04 PST</pubDate>
			<author>mntbighker</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4497/14625</guid>
		</item>
		<item>
			<title>Migrating to different Environment.</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4500/14624</link>
			<description>&lt;p&gt;i think you got your help in #splunk IRC this morning; please ask any future questions at &lt;a href=&quot;http://answers.splunk.com&quot; onclick=&quot;window.open(this.href, '_blank'); return false;&quot;&gt;http://answers.splunk.com&lt;/a&gt;; it supersedes this forum.&lt;/p&gt;

</description>
			<pubDate>Mon, 07 Mar 2011 16:18:17 PST</pubDate>
			<author>rachel</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4500/14624</guid>
		</item>
		<item>
			<title>Migrating to different Environment.</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4500/14623</link>
			<description>&lt;p&gt;Hi, &lt;br /&gt;
    I am having splunk in one environment(network) with forwarders and have configured lot of searches, alerts and System Configurations ( in Splunk -&amp;gt; Manager )  .. Now I want another very similar setup on another network? Is it possible to export the configurations of the existing Environment and import in another new environment ?? Can I do that ..&lt;/p&gt;

</description>
			<pubDate>Mon, 07 Mar 2011 04:56:44 PST</pubDate>
			<author>karthikkumar</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4500/14623</guid>
		</item>
		<item>
			<title>splunk error</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4498/14622</link>
			<description>&lt;p&gt;Same problem here..&lt;/p&gt;

</description>
			<pubDate>Sun, 06 Mar 2011 17:07:38 PST</pubDate>
			<author>lubinski</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4498/14622</guid>
		</item>
		<item>
			<title>Unable to add Data Inputs due to error</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/3007/14621</link>
			<description>&lt;p&gt;That should read &lt;em&gt;psturge said:&lt;/em&gt;&lt;br /&gt;
hah, oops.&lt;/p&gt;

</description>
			<pubDate>Thu, 03 Mar 2011 12:49:19 PST</pubDate>
			<author>dprice01</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/3007/14621</guid>
		</item>
		<item>
			<title>Unable to add Data Inputs due to error</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/3007/14620</link>
			<description>&lt;p&gt;permalink said: &amp;quot;For production environments, use a &lt;strong&gt;proper log management product&lt;/strong&gt; like Honeycomb Technologies to feed into Splunk. It will scale much better, and you full remote management, native file access monitoring, and really cool reports/data mining too.&amp;quot;&lt;/p&gt;

&lt;p&gt;Isn't that was Splunk is supposed to be, or am I missing something?  If honeycomb comes back with the right price, what motivation do I have to keep splunk around?&lt;/p&gt;

</description>
			<pubDate>Thu, 03 Mar 2011 12:47:22 PST</pubDate>
			<author>dprice01</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/3007/14620</guid>
		</item>
		<item>
			<title>How can I read a MySQL table as a Splunk input?</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/1609/14618</link>
			<description>&lt;p&gt;did you manage to suceed? I am having the same problem?&lt;br /&gt;
can you please post how.&lt;/p&gt;

</description>
			<pubDate>Wed, 02 Mar 2011 04:46:37 PST</pubDate>
			<author>nunopratas</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/1609/14618</guid>
		</item>
		<item>
			<title>Splunk - Cannot Update Permissions - Error</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4473/14616</link>
			<description>&lt;p&gt;I'm seeing this in 4.1.7 too.  How did you work around it?  Which config file holds this setting?&lt;/p&gt;

</description>
			<pubDate>Sun, 27 Feb 2011 12:59:15 PST</pubDate>
			<author>hughkelley</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4473/14616</guid>
		</item>
		<item>
			<title>splunk error</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4498/14615</link>
			<description>&lt;p&gt;I  have got next message&lt;/p&gt;

&lt;p&gt;&amp;quot;received event for unconfigured/disabled index='_audit' with source='source::audittrail' host='host::ieprodweb01' sourcetype='sourcetype::audittrail'.(I got that message on Forwarder server and Receiver server)&lt;/p&gt;

&lt;p&gt;I think I have got that message when I have configured Light Forwader and Receiver.&lt;/p&gt;

&lt;p&gt;I have installed on my forwader server: splunk 4.1.6 trial version&lt;br /&gt;
On Splunk server(Receiver),I have installed splunk 4.1.6 free license.&lt;/p&gt;

&lt;p&gt;Can you help me to fix that problem.&lt;/p&gt;

&lt;p&gt;Regards,&lt;/p&gt;

&lt;p&gt;John&lt;/p&gt;

</description>
			<pubDate>Sat, 26 Feb 2011 12:17:24 PST</pubDate>
			<author>bwenge</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4498/14615</guid>
		</item>
		<item>
			<title>Default password fails</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4497/14614</link>
			<description>&lt;p&gt;I have installed splunk on about 10 Linux boxes in the past week. 2 have been 64bit kernels. The second 64bit one installs and appears to start normally. But the default &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/user:pass&quot;&gt;user:pass&lt;/a&gt; refuse to work? Anybody have any idea what might be going on?&lt;/p&gt;

&lt;p&gt;[Revised on Fri, 25 Feb 2011 17:59:43 -0800]&lt;/p&gt;

&lt;p&gt;I can set up forwarding to my Splunk log server. I can get SSL to work for that connection. But I can't disable the local index or turn on lightforward because it says my authentication fails.&lt;/p&gt;

</description>
			<pubDate>Fri, 25 Feb 2011 17:29:45 PST</pubDate>
			<author>mntbighker</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4497/14614</guid>
		</item>
		<item>
			<title>monitor apache access log on my linux splunk server</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4495/14613</link>
			<description>&lt;p&gt;start here:&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://www.splunk.com/base/Documentation/latest/Admin/WhatSplunkcanmonitor&quot;&gt;http://www.splunk.com/base/Documentation/latest/Admin/WhatSplunkcanmonitor&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;and then ask future questions at answers.splunk.com :)&lt;/p&gt;

</description>
			<pubDate>Fri, 25 Feb 2011 16:06:46 PST</pubDate>
			<author>rachel</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4495/14613</guid>
		</item>
		<item>
			<title>Audit index has ldap user info.  I would like to see ldap Full Name field</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4496/14612</link>
			<description>&lt;p&gt;you could probably do this with lookups, search for that in the Splunk documentation.&lt;/p&gt;

</description>
			<pubDate>Fri, 25 Feb 2011 16:03:30 PST</pubDate>
			<author>rachel</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4496/14612</guid>
		</item>
		<item>
			<title>Audit index has ldap user info.  I would like to see ldap Full Name field</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4496/14611</link>
			<description>&lt;p&gt;I am searching through the _audit index and I am seeing a lot of nice stuff.  The problem I am having is it uses the user id for the audit information.  That is fine but I would like to be able to see the Full Name from ldap as well.  Is there a way to pull that information from ldap within my query?&lt;/p&gt;

</description>
			<pubDate>Fri, 25 Feb 2011 15:10:50 PST</pubDate>
			<author>brantramey</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4496/14611</guid>
		</item>
		<item>
			<title>monitor apache access log on my linux splunk server</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4495/14609</link>
			<description>&lt;p&gt;I have a linux server with apache installed.I will like to monitor its access logs on my splunk serverrunning on linux.How to do it&lt;/p&gt;

</description>
			<pubDate>Wed, 23 Feb 2011 23:34:41 PST</pubDate>
			<author>bwenge</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4495/14609</guid>
		</item>
		<item>
			<title>how do i convert the Enterprise licence to free</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/3492/14608</link>
			<description>&lt;p&gt;Command line?&lt;/p&gt;

</description>
			<pubDate>Tue, 22 Feb 2011 17:08:15 PST</pubDate>
			<author>mntbighker</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/3492/14608</guid>
		</item>
		<item>
			<title>Can't download apps within Splunk</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4494/14606</link>
			<description>&lt;p&gt;Hi,&lt;/p&gt;

&lt;p&gt;Just installed Splunk on Ubuntu Server, 64 bit. Everything looks good but I can't download the apps (&lt;a href=&quot;http://xxx.xxx.xxx.xxx:8000/en-GB/app/launcher/home&quot; onclick=&quot;window.open(this.href, '_blank'); return false;&quot;&gt;http://xxx.xxx.xxx.xxx:8000/en-GB/app/launcher/home&lt;/a&gt;). I get &amp;quot;Invalid username or password&amp;quot; error when I enter my www.splunk.com credentials. I've logged out and back in to the Splunk website to double-check they're correct.&lt;/p&gt;

&lt;p&gt;Any ideas?&lt;/p&gt;

&lt;p&gt;David.&lt;/p&gt;

</description>
			<pubDate>Tue, 22 Feb 2011 01:49:12 PST</pubDate>
			<author>dcaldwell</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4494/14606</guid>
		</item>
		<item>
			<title>Reading Exchange log files only 15 days or newer?</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4493/14604</link>
			<description>&lt;p&gt;With limited resources but many Exchange servers, I wish to only index the last 15 days of message tracking logs and new logs as they come in for a few days.  However, these live log directories contain 90 days of logs and the splunk server and license cannot handle this amount of input.  What is the recommended way to accomplish this?&lt;/p&gt;

</description>
			<pubDate>Mon, 21 Feb 2011 12:03:58 PST</pubDate>
			<author>panderson</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4493/14604</guid>
		</item>
		<item>
			<title>F5 LTM</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/3878/14603</link>
			<description>&lt;p&gt;F5 fully supports sending the log data out via syslog&lt;/p&gt;

</description>
			<pubDate>Wed, 16 Feb 2011 13:15:45 PST</pubDate>
			<author>kentperrier</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/3878/14603</guid>
		</item>
		<item>
			<title>Installing multiple instances on Centos via RPM</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4492/14602</link>
			<description>&lt;p&gt;Hey,&lt;/p&gt;

&lt;p&gt;I'm trying to install 2 instances of Splunk on a linux machine having migrated from a windows machine. This process was successful on the windows machine, but I'm having a little trouble on the linux machine.&lt;/p&gt;

&lt;p&gt;I tried following the directions given by&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://www.splunk.com/wiki/Community:Run_multiple_Splunks_on_one_machine&quot;&gt;http://www.splunk.com/wiki/Community:Run_multiple_Splunks_on_one_machine&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;by running the command&lt;/p&gt;

&lt;p&gt;rpm -i --prefix=/opt/new_directory splunk_package_name.rpm&lt;/p&gt;

&lt;p&gt;but got something in the order of&lt;/p&gt;

&lt;p&gt;package splunk already installed&lt;/p&gt;

&lt;p&gt;from rpm.&lt;/p&gt;

&lt;p&gt;Any help would be greatly appreciated. Thanks.&lt;/p&gt;

</description>
			<pubDate>Tue, 15 Feb 2011 14:32:01 PST</pubDate>
			<author>williamhutson</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4492/14602</guid>
		</item>
		<item>
			<title>CRASH: Faulting application splunkd.exe, version 0.0.0.0, faulting module msvcr80.dll, version 8.0.5</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/3889/14599</link>
			<description>&lt;p&gt;We have tried the above steps of stopping splunkdaemon services ( infact uninstalled splunk and re-installed), after a particular time it starts showing these errors&lt;/p&gt;

&lt;p&gt;Do we have a fix for this yet?&lt;/p&gt;

&lt;p&gt;Thanks,&lt;/p&gt;

</description>
			<pubDate>Fri, 11 Feb 2011 17:13:35 PST</pubDate>
			<author>rvenkatesh</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/3889/14599</guid>
		</item>
		<item>
			<title>reached the maximum license violations for this time period</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4490/14598</link>
			<description>&lt;p&gt;&lt;a href=&quot;http://answers.splunk.com/questions/322/what-happens-when-i-exceed-my-licensed-limit&quot; onclick=&quot;window.open(this.href, '_blank'); return false;&quot;&gt;http://answers.splunk.com/questions/322/what-happens-when-i-exceed-my-licensed-limit&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://www.splunk.com/base/Documentation/latest/Installation/AboutSplunklicenses#License_violations&quot;&gt;http://www.splunk.com/base/Documentation/latest/Installation/AboutSplunklicenses#License_violations&lt;/a&gt;&lt;/p&gt;

</description>
			<pubDate>Thu, 10 Feb 2011 16:01:01 PST</pubDate>
			<author>gkanapathy</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4490/14598</guid>
		</item>
		<item>
			<title>reached the maximum license violations for this time period</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4490/14597</link>
			<description>&lt;p&gt;Hello,&lt;/p&gt;

&lt;p&gt;I had to put a couple of servers in &amp;quot;trivial&amp;quot; mode (verbose++) and this pushed the amount of logs higher than the 500MB/day limit for the free license.&lt;/p&gt;

&lt;p&gt;I not have a &amp;quot;reached the maximum license violations for this time period&amp;quot; blue banner. Any idea about how long &amp;quot;this time period&amp;quot; is? It's now been 10 days since the last violation, I'm now back to 113MB/day. &lt;br /&gt;
What does the &amp;quot;Violation Period: 30&amp;quot; below means? I suppose it's 30 days, but of what? you can have 3 violations in 30 days? you will be locked out for 30 days?&lt;/p&gt;

&lt;p&gt;{{&lt;/p&gt;

&lt;ol&gt;
    &lt;li&gt;/opt/splunk/bin/splunk show license &lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Current Daily Usage Amount:     113254140&lt;br /&gt;
Expiration date:         2037-01-20T14:30:11-0500&lt;br /&gt;
Expiration State:&lt;br /&gt;
License level:             500 MB&lt;br /&gt;
Product:             free&lt;br /&gt;
License violations:         &lt;br /&gt;
        2011-02-01T00:04:32-0500 License violation #4&lt;br /&gt;
        2011-01-31T00:00:35-0500 License violation #3&lt;br /&gt;
        2011-01-30T00:04:40-0500 License violation #2&lt;br /&gt;
        2011-01-29T00:00:15-0500 License violation #1&lt;br /&gt;
Max Violations:         3&lt;br /&gt;
Peak usage:             1103 MB&lt;br /&gt;
Days remaining:         9475 day(s)&lt;br /&gt;
Violation Period:         30&lt;br /&gt;
}}&lt;/p&gt;

&lt;p&gt;Thanks&lt;/p&gt;

&lt;p&gt;Olivier&lt;/p&gt;

</description>
			<pubDate>Thu, 10 Feb 2011 13:22:57 PST</pubDate>
			<author>0l1v1er</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4490/14597</guid>
		</item>
		<item>
			<title>LightWeightForwarder stops sending data</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4483/14596</link>
			<description>&lt;p&gt;i recommend you guys post your questions to answers.splunk.com; it supersedes this forum.&lt;/p&gt;

</description>
			<pubDate>Tue, 08 Feb 2011 14:23:32 PST</pubDate>
			<author>rachel</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4483/14596</guid>
		</item>
		<item>
			<title>LightWeightForwarder stops sending data</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4483/14595</link>
			<description>&lt;p&gt;Have you been able to find a solution to this issue? I'm experiencing the same problem.&lt;br /&gt;
Additionally what I've found is when I run &amp;quot;netstat -an|grep &amp;lt;port&amp;gt;&amp;quot; on the forwarding server there is usually a few connections in a FIN_WAIT state. &lt;br /&gt;
I'm trying to track this down on the server side.&lt;/p&gt;

&lt;p&gt;Thank you&lt;/p&gt;

</description>
			<pubDate>Tue, 08 Feb 2011 13:12:58 PST</pubDate>
			<author>AppServices</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4483/14595</guid>
		</item>
		<item>
			<title>More SNMP Windows frustration..</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4489/14594</link>
			<description>&lt;p&gt;It would be nice if you shared what Splunk shares with you.  I am about to undertake a similar task ie: getting Splunk that is installed on Windows Server 2008 64-bit to catch SNMP traps from various devices and was hoping this thread will provide me some answers.&lt;/p&gt;

</description>
			<pubDate>Sat, 05 Feb 2011 15:29:13 PST</pubDate>
			<author>cbdick</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4489/14594</guid>
		</item>
		<item>
			<title>Indexing a CSV data file with more than one set of information</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4486/14593</link>
			<description>&lt;p&gt;hi, i recommend you ask this over at answers.splunk.com -- it is much more active and supersedes this forum.&lt;/p&gt;

</description>
			<pubDate>Wed, 02 Feb 2011 10:47:58 PST</pubDate>
			<author>rachel</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4486/14593</guid>
		</item>
		<item>
			<title>More SNMP Windows frustration..</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4489/14592</link>
			<description>&lt;p&gt;never mind, splunk are contacting me about this issue and how to get splunk for windows setup to capture data correctly.&lt;/p&gt;

&lt;p&gt;feel free to close / delete this post.&lt;/p&gt;

</description>
			<pubDate>Tue, 01 Feb 2011 08:02:39 PST</pubDate>
			<author>kristiaan_d</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4489/14592</guid>
		</item>
		<item>
			<title>More SNMP Windows frustration..</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4489/14591</link>
			<description>&lt;p&gt;Hi everyone, i need some help as i am slowly starting to go off splunk and its logging all of this due to SNMP...&lt;/p&gt;

&lt;p&gt;All i want to-do is setup Splunk so it will index all the SNMP data that my firewall pumps out, (its a watchguard firebox). i have been looking into this and so far im completely baffled as to why this seems to difficult.&lt;/p&gt;

&lt;p&gt;i have failed completly to setup NET-SNMP or SNMPTrapd or what ever its called, the help files and manuals are not setup in any way to help out someone like me who has never used the software.&lt;/p&gt;

&lt;p&gt;Splunks website states i should ammend a config file&lt;/p&gt;

&lt;p&gt;C:\usr\etc\snmp\snmptrapd.conf&lt;/p&gt;

&lt;p&gt;this file does not exist in my setup, i have an SNMP.conf file...&lt;/p&gt;

&lt;p&gt;all i want to-do is setup splunk to capture the data from my firewall, why is this being made so difficult? i would have thought that a system developed to capture and index data would have the ability to capture SNMP traffic natively?&lt;/p&gt;

&lt;p&gt;This appears to be an oversight of someone in project planning, there decision rather to farm it off on some half baked un-usable linux conversion that is no use to someone with little linux config experience.&lt;/p&gt;

&lt;p&gt;dont get me wrong if the net-snmp project had a nice write up on how to configure it for windows and to test its working i would not be writing this now but splunk chose to suggest them...&lt;/p&gt;

&lt;p&gt;on a final rant, are we ever likely to see someone at splunk write some native SNMP handling into it? might be an idea been as SNMP is encorporated into 99% of devices splunk is designed to index the data from?&lt;/p&gt;

&lt;p&gt;kris&lt;/p&gt;

</description>
			<pubDate>Tue, 01 Feb 2011 06:41:46 PST</pubDate>
			<author>kristiaan_d</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4489/14591</guid>
		</item>
		<item>
			<title>Indexing a CSV data file with more than one set of information</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4486/14587</link>
			<description>&lt;p&gt;Hi All,&lt;/p&gt;

&lt;p&gt;Just curious about the best method to index a CSV file with multiple sets of data inside?&lt;/p&gt;

&lt;p&gt;The basic format of the whole file is&lt;/p&gt;

&lt;p&gt;I,&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/DataSet1&quot;&gt;DataSet1&lt;/a&gt;_FieldName1,&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/DataSet1&quot;&gt;DataSet1&lt;/a&gt;_FieldName2,&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/DataSet1&quot;&gt;DataSet1&lt;/a&gt;_FieldName3&lt;br /&gt;
D,this,54,fred&lt;br /&gt;
D,this,87,barry&lt;br /&gt;
I,&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/DataSet2&quot;&gt;DataSet2&lt;/a&gt;_FieldName1,&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/DataSet2&quot;&gt;DataSet2&lt;/a&gt;_FieldName2,&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/DataSet2&quot;&gt;DataSet2&lt;/a&gt;_FieldName3&lt;br /&gt;
D,784,moreInfo,thatData&lt;br /&gt;
D,5443,moreInfo2,thisData&lt;br /&gt;
D,524,moreInfo2,theOtherData&lt;br /&gt;
I,&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/DataSet3&quot;&gt;DataSet3&lt;/a&gt;_FieldName1,&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/DataSet3&quot;&gt;DataSet3&lt;/a&gt;_FieldName2&lt;br /&gt;
D,Wow,&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/SoMuchData&quot;&gt;SoMuchData&lt;/a&gt;&lt;br /&gt;
D,Really,&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/MoreData&quot;&gt;MoreData&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;and on and on it goes with about 5 sets of data.&lt;/p&gt;

&lt;p&gt;I have been playing around with regular expressions trying to catch one particular set of data but have had no luck yet.&lt;/p&gt;

&lt;p&gt;Can someone point me in the right direction as to how I would index data files such as this?&lt;/p&gt;

&lt;p&gt;[Revised on Sun, 30 Jan 2011 19:13:52 -0800]&lt;/p&gt;

&lt;p&gt;Another note as you can see the first field of each row determines if the row is a header/index row or a data row&lt;br /&gt;
I = Index/Header row&lt;br /&gt;
D = Data row&lt;/p&gt;

</description>
			<pubDate>Sun, 30 Jan 2011 19:12:32 PST</pubDate>
			<author>phoenixdigital</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4486/14587</guid>
		</item>
		<item>
			<title>JMX/JMS</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/1413/14583</link>
			<description>&lt;p&gt;JMX/JMS would rule...&lt;/p&gt;

</description>
			<pubDate>Wed, 19 Jan 2011 15:04:47 PST</pubDate>
			<author>jordancrombie</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/1413/14583</guid>
		</item>
		<item>
			<title>unable to share dashboard/view</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4484/14580</link>
			<description>&lt;p&gt;I was able to find the answer here:&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://answers.splunk.com/questions/5309/can-a-regular-user-promote-views-dashboards-to-be-app-level-visible&quot; onclick=&quot;window.open(this.href, '_blank'); return false;&quot;&gt;http://answers.splunk.com/questions/5309/can-a-regular-user-promote-views-dashboards-to-be-app-level-visible&lt;/a&gt;&lt;/p&gt;

</description>
			<pubDate>Fri, 14 Jan 2011 11:00:10 PST</pubDate>
			<author>mdurkin</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4484/14580</guid>
		</item>
		<item>
			<title>unable to share dashboard/view</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4484/14579</link>
			<description>&lt;p&gt;Hi,&lt;/p&gt;

&lt;p&gt;I have a view that belongs to the search app that I am trying to share with other users.  I checked and my user does have write permission to the search app.  When I try to save the new permission settings, I get hte following message:&lt;/p&gt;

&lt;p&gt;Splunk could not update permissions for resource data/ui/views Client is not authorized to perform requested action&lt;/p&gt;

&lt;p&gt;I look in web_service.log and see the following error messages:&lt;/p&gt;

&lt;p&gt;2011-01-14 13:16:07,358 ERROR   [4d3092e756a473eac] admin:1334 - Splunk could not update ACL with the following params: {'owner': u'testuser', 'sharing': u'app', 'perms.read': u'*'}&lt;br /&gt;
2011-01-14 13:16:07,446 INFO    [4d3092e756a473eac] cached:69 - memoized decorator used on function &amp;lt;function getEntities at 0x8a121b4&amp;gt; with non hashable arguments&lt;/p&gt;

&lt;p&gt;If it matters I am running Splunk 4.1.2.&lt;/p&gt;

&lt;p&gt;-Mike&lt;/p&gt;

</description>
			<pubDate>Fri, 14 Jan 2011 10:18:09 PST</pubDate>
			<author>mdurkin</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4484/14579</guid>
		</item>
		<item>
			<title>LightWeightForwarder stops sending data</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4483/14577</link>
			<description>&lt;p&gt;I have a Indexer that's receiving data from some servers but one of them, it stops sending data after a while.&lt;br /&gt;
To see if it was a bug or something I updated the splunk version to the latest one, and it started sending but then it stopped and even if I restart splunk it doesn't keep sending. I wen through the splunkd.log and there are some events that keep repeating over and over again and I think the problem lies here:&lt;/p&gt;

&lt;p&gt;&lt;tt&gt;01-05-2011 19:17:03.103 WARN  &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TcpOutputProc&quot;&gt;TcpOutputProc&lt;/a&gt; - &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TcpSendThread&quot;&gt;TcpSendThread&lt;/a&gt;: Connection to server XXX.XXX.XXX.XXX:9995, fd:1264 lost - retrying: winsock error 0&lt;br /&gt;
01-05-2011 19:17:03.103 INFO  &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TcpOutputProc&quot;&gt;TcpOutputProc&lt;/a&gt; - attempting to connect to XXX.XXX.XXX.XXX:9995...&lt;br /&gt;
01-05-2011 19:17:03.119 INFO  &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TcpOutputProc&quot;&gt;TcpOutputProc&lt;/a&gt; - Connected to XXX.XXX.XXX.XXX:9995 &lt;br /&gt;
01-05-2011 19:17:03.119 WARN  &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TcpOutputProc&quot;&gt;TcpOutputProc&lt;/a&gt; - &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TcpSendThread&quot;&gt;TcpSendThread&lt;/a&gt;: Connection to server XXX.XXX.XXX.XXX:9995, fd:1328 lost - retrying: winsock error 0&lt;br /&gt;
01-05-2011 19:17:03.119 INFO  &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TcpOutputProc&quot;&gt;TcpOutputProc&lt;/a&gt; - attempting to connect to XXX.XXX.XXX.XXX:9995...&lt;br /&gt;
01-05-2011 19:17:03.135 INFO  &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TcpOutputProc&quot;&gt;TcpOutputProc&lt;/a&gt; - Connected to XXX.XXX.XXX.XXX:9995 &lt;br /&gt;
01-05-2011 19:17:03.135 WARN  &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TcpOutputProc&quot;&gt;TcpOutputProc&lt;/a&gt; - &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TcpSendThread&quot;&gt;TcpSendThread&lt;/a&gt;: Connection to server XXX.XXX.XXX.XXX:9995, fd:1256 lost - retrying: winsock error 0&lt;br /&gt;
01-05-2011 19:17:33.137 INFO  &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TcpOutputProc&quot;&gt;TcpOutputProc&lt;/a&gt; - attempting to connect to XXX.XXX.XXX.XXX:9995...&lt;br /&gt;
01-05-2011 19:17:33.152 INFO  &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TcpOutputProc&quot;&gt;TcpOutputProc&lt;/a&gt; - Connected to XXX.XXX.XXX.XXX:9995&lt;/tt&gt;&lt;/p&gt;

</description>
			<pubDate>Tue, 11 Jan 2011 06:57:13 PST</pubDate>
			<author>arapozo</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4483/14577</guid>
		</item>
		<item>
			<title>Splunk is complaining about a missing index...that is there</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/3997/14576</link>
			<description>&lt;p&gt;hi, i recommend posting this to answers.splunk.com if you haven't already. this forum is superseded by answers.splunk.com.&lt;/p&gt;

</description>
			<pubDate>Mon, 10 Jan 2011 12:54:25 PST</pubDate>
			<author>rachel</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/3997/14576</guid>
		</item>
		<item>
			<title>Splunk &quot;one-way-drop&quot; that can receive data, but cannot be compromised by a hacker through some acci</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4482/14574</link>
			<description>&lt;p&gt;Hello&lt;/p&gt;

&lt;p&gt;Would Splunk work if it's installed on a Linux system based upon UDP so one-way datagrams can be used forward to a device that cannot respond?&lt;/p&gt;

&lt;p&gt;Any feedback is appreciated very much. Thank you!&lt;/p&gt;

&lt;p&gt;John&lt;/p&gt;

&lt;p&gt;Some informations about that topic:&lt;/p&gt;

&lt;p&gt;Under 3.6 of Robert Grahams sniffer, e..g. found under &lt;a href=&quot;http://newdata.box.sk/2001/jan/sniffing-faq.htm&quot; onclick=&quot;window.open(this.href, '_blank'); return false;&quot;&gt;http://newdata.box.sk/2001/jan/sniffing-faq.htm&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;-&amp;gt;  Why would I want to do this?&lt;br /&gt;
-&amp;gt;  For security reasons. Networking is full of accidents waiting to happen, which &lt;br /&gt;
-&amp;gt;  crackers/hackers exploit in order to break into systems. Clipping the transmit &lt;br /&gt;
-&amp;gt;  wires on an Ethernet adapters generates a &amp;quot;one-way-drop&amp;quot; that can receive &lt;br /&gt;
-&amp;gt;  data, but cannot be compromised by a hacker through some accident.&lt;/p&gt;

&lt;p&gt;-&amp;gt;  Examples:&lt;br /&gt;
-&amp;gt;   * Receiving syslog messages and storing them to a non-compromisable &lt;br /&gt;
-&amp;gt;  system. The 'syslog' protocol is used by numerous UNIX services to log security &lt;br /&gt;
-&amp;gt;  events, and is based upon UDP so one-way datagrams can be used forward to &lt;br /&gt;
-&amp;gt;  a device that cannot respond. ARP and route tables need to be manually &lt;br /&gt;
-&amp;gt;  configured to ensure this operation.&lt;/p&gt;

&lt;p&gt;-&amp;gt;   * Similarly receiving SNMP traps, which also use UDP. Many systems generate&lt;br /&gt;
-&amp;gt;   SNMP traps in response to security related events.&lt;/p&gt;

</description>
			<pubDate>Sat, 08 Jan 2011 00:58:01 PST</pubDate>
			<author>hans135</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4482/14574</guid>
		</item>
		<item>
			<title>Splunk is complaining about a missing index...that is there</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/3997/14572</link>
			<description>&lt;p&gt;I'm running v 4.1.6 and getting a similar error:&lt;br /&gt;
ERROR &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/IndexProcessor&quot;&gt;IndexProcessor&lt;/a&gt; - received event for unconfigured/disabled index='_audit' with source='source::audittrail' host='host::tm22-s00261' sourcetype='sourcetype::audittrail'&lt;/p&gt;

&lt;p&gt;I'm guessing that we've nuked something in one of the config files (we deploy Splunk via chef and write our own config file) but I don't know what's missing.&lt;/p&gt;

</description>
			<pubDate>Tue, 04 Jan 2011 12:41:16 PST</pubDate>
			<author>groupon</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/3997/14572</guid>
		</item>
		<item>
			<title>Server additions problem</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4374/14565</link>
			<description>&lt;p&gt;&amp;aelig;&amp;nbsp;&amp;aelig;&amp;sup3;&amp;aring;&amp;aring;&amp;frac34;&amp;aelig;&amp;deg;&amp;aelig;&amp;reg;&amp;iuml;&amp;frac14;In handler 'win-wmi-enum-eventlogs': External handler failed with code '1' and output: Traceback (most recent call last): File &amp;quot;D:\Program Files\Splunk\bin\runScript.py&amp;quot;, line 69, in &amp;lt;module&amp;gt; execfile(REAL_SCRIPT_NAME) File &amp;quot;D:\Program Files\Splunk\etc\system\bin\wmi_enum_eventlogs.py&amp;quot;, line 28, in &amp;lt;module&amp;gt; admin.init(&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/WMIFindEventLog&quot;&gt;WMIFindEventLog&lt;/a&gt;, admin.CONTEXT_NONE) File &amp;quot;D:\Program Files\Splunk\Python-2.6\Lib\site-packages\splunk\admin.py&amp;quot;, line 79, in init msgNode.text = str(exMsg) File &amp;quot;lxml.etree.pyx&amp;quot;, line 821, in lxml.etree._Element.text.&lt;u&gt;set&lt;/u&gt; (src/lxml/lxml.etree.c:32905) File &amp;quot;apihelpers.pxi&amp;quot;, line 650, in lxml.etree._setNodeText (src/lxml/lxml.etree.c:15144) File &amp;quot;apihelpers.pxi&amp;quot;, line 1247, in lxml.etree._utf8 (src/lxml/lxml.etree.c:19727) &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/ValueError&quot;&gt;ValueError&lt;/a&gt;: All strings must be XML compatible: Unicode or ASCII, no NULL bytes .&lt;/p&gt;

</description>
			<pubDate>Sun, 26 Dec 2010 19:13:22 PST</pubDate>
			<author>xiaochuxi929</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4374/14565</guid>
		</item>
		<item>
			<title>Splunk seems to be ignoring props.conf and transforms.conf</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4457/14563</link>
			<description>&lt;p&gt;Which app are you putting this in?  Try putting this in the search app.&lt;/p&gt;

&lt;p&gt;Dan&lt;/p&gt;

</description>
			<pubDate>Sat, 18 Dec 2010 15:35:48 PST</pubDate>
			<author>dps</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4457/14563</guid>
		</item>
		<item>
			<title>Splunk - Cannot Update Permissions - Error</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/4473/14560</link>
			<description>&lt;p&gt;Splunk support was nice enough to look into this for me...&lt;br /&gt;
So, Just FYI if anyone else has noticed this.&lt;/p&gt;

&lt;p&gt;After further review, it looks like the problem is that UI-level permissions should not apply to data inputs, and that the manager page for the &amp;acirc;event log collections&amp;acirc; is improperly built in 4.1.6. The status column should definitely only show the &amp;acirc;enable&amp;acirc; and &amp;acirc;disable&amp;acirc; actions instead of UI-permissions.&lt;/p&gt;

</description>
			<pubDate>Tue, 14 Dec 2010 06:04:39 PST</pubDate>
			<author>scongdon</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/4473/14560</guid>
		</item>
		<item>
			<title>Windows 2008 Event Descriptions not displayed</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/3418/14558</link>
			<description>&lt;p&gt;same issue with 4.1.6....any resolutions?&lt;/p&gt;

</description>
			<pubDate>Mon, 13 Dec 2010 14:33:23 PST</pubDate>
			<author>jkanaszka</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/3418/14558</guid>
		</item>
		<item>
			<title>splunkweb fails to start</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/2625/14554</link>
			<description>&lt;p&gt;hey there! i recommend you ask your questions over at answers.splunk.com, it's much more active than these forums.&lt;/p&gt;

</description>
			<pubDate>Tue, 30 Nov 2010 17:28:40 PST</pubDate>
			<author>rachel</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/2625/14554</guid>
		</item>
	</channel>
</rss>

