<?xml version="1.0" ?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
	<channel>
		<title>Splunk Base : SplunkAdministration : #2814</title>
		<link>http://www.splunk.com/support/forum:SplunkAdministration/2814</link>
		<description></description>
		<pubDate>Mon, 13 Feb 2012 19:36:35 PST</pubDate>
		<lastBuildDate>Mon, 13 Feb 2012 19:36:35 PST</lastBuildDate>
		<language>en-us</language>
		<copyright>http://creativecommons.org/licenses/by-nc-nd/2.5/</copyright>
		<item>
			<title>Splunk to monitor Oracle logs</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/2814/12787</link>
			<description>&lt;p&gt;Subhanjan,&lt;/p&gt;

&lt;p&gt;Can u guide me in extracting logs from oracle database(Solaris-Forwarder) to windows server 2003 (Splunk Indexer) ? &lt;br /&gt;
      Or can u refer the docs to me ?&lt;/p&gt;

&lt;p&gt;Thanks,&lt;br /&gt;
Mateen.&lt;/p&gt;

</description>
			<pubDate>Sat, 23 Jan 2010 05:15:46 PST</pubDate>
			<author>mateenbebal</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/2814/12787</guid>
		</item>
		<item>
			<title>Splunk to monitor Oracle logs</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/2814/9054</link>
			<description>&lt;p&gt;Thanks a lot.I cracked it myself going through the docs..&lt;/p&gt;

</description>
			<pubDate>Sat, 06 Jun 2009 22:42:33 PDT</pubDate>
			<author>subhanjan</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/2814/9054</guid>
		</item>
		<item>
			<title>Splunk to monitor Oracle logs</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/2814/9001</link>
			<description>&lt;p&gt;On server B, can you show me:&lt;/p&gt;

&lt;p&gt;- $SPLUNK_HOME/etc/system/local/inputs.conf&lt;/p&gt;

&lt;p&gt;- $SPLUNK_HOME/etc/system/local/outputs.conf&lt;/p&gt;

&lt;p&gt;- the output of 'splunk list monitor'&lt;/p&gt;

&lt;p&gt;On server A, can you show me:&lt;/p&gt;

&lt;p&gt;- $SPLUNK_HOME/etc/system/local/inputs.conf&lt;/p&gt;

&lt;p&gt;Does the alert log have a header or any binary data in it?  I don't believe it does, but it doesn't hurt to check.&lt;/p&gt;

</description>
			<pubDate>Mon, 01 Jun 2009 09:52:35 PDT</pubDate>
			<author>araitz</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/2814/9001</guid>
		</item>
		<item>
			<title>Splunk to monitor Oracle logs</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/2814/8995</link>
			<description>&lt;p&gt;Hi,&lt;br /&gt;
We have a splunk server  Server A with receiving enabled from Server B.In Server B we have enabled forwarding and have set the &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/LightForwarder&quot;&gt;LightForwarder&lt;/a&gt; mode.In Server B we have enabled Data Inputs-&amp;gt;Files and Directories-&amp;gt;Add Input and gave the customized path /oracle/test/admin/bdump/alert_test.log.&lt;br /&gt;
We are unable to see the path or logs in &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/ServerA&quot;&gt;ServerA&lt;/a&gt;.&lt;br /&gt;
In &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/ServerB&quot;&gt;ServerB&lt;/a&gt; we can see the following message in Splunk log&lt;/p&gt;

&lt;p&gt;05-31-2009 08:14:46.697 INFO  &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/SavedSplunker&quot;&gt;SavedSplunker&lt;/a&gt; - &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/SavedSplunker&quot;&gt;SavedSplunker&lt;/a&gt;::main: Found 0 saved searches ready to run&lt;/p&gt;

&lt;p&gt;05-31-2009 08:15:16.698 INFO  &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/SavedSplunker&quot;&gt;SavedSplunker&lt;/a&gt; - &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/SavedSplunker&quot;&gt;SavedSplunker&lt;/a&gt;::main: Found 0 saved searches ready to run&lt;/p&gt;

&lt;p&gt;Can we monitor my Oracle logs?Did we missed something in configuration.&lt;/p&gt;

</description>
			<pubDate>Sat, 30 May 2009 21:49:17 PDT</pubDate>
			<author>subhanjan</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/2814/8995</guid>
		</item>
	</channel>
</rss>

