<?xml version="1.0" ?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
	<channel>
		<title>Splunk Base : SplunkGeneral</title>
		<link>http://www.splunk.com/support/forum:SplunkGeneral</link>
		<description>General discussion on all things Splunk. </description>
		<pubDate>Mon, 13 Feb 2012 11:20:43 PST</pubDate>
		<lastBuildDate>Mon, 13 Feb 2012 11:20:43 PST</lastBuildDate>
		<language>en-us</language>
		<copyright>http://creativecommons.org/licenses/by-nc-nd/2.5/</copyright>
		<item>
			<title>Masking credit card numbers</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4507/14651</link>
			<description>&lt;p&gt;While I'm able to mask 16 digit numbers I would like a more sophisticated approach as there are some numbers in that range that are not credit card numbers that I don't want to mask, such as error codes.  Is anyone utilizing the Luhn Algorithm (&lt;a href=&quot;http://rosettacode.org/wiki/Luhn_test_of_credit_card_numbers&quot; onclick=&quot;window.open(this.href, '_blank'); return false;&quot;&gt;http://rosettacode.org/wiki/Luhn_test_of_credit_card_numbers&lt;/a&gt;) or something better than my current approach?&lt;/p&gt;

</description>
			<pubDate>Fri, 08 Apr 2011 13:02:49 PDT</pubDate>
			<author>cjs226</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4507/14651</guid>
		</item>
		<item>
			<title>Live tail</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4506/14650</link>
			<description>&lt;p&gt;Feeling like this is a really silly question, but I just installed 4.2 and bought a 500MB license. I was running 3.x and using Live Tail all the time.&lt;/p&gt;

&lt;p&gt;I can't find live tail in 4.2 can someone point me to the URL path?&lt;/p&gt;

&lt;p&gt;Thanks,&lt;br /&gt;
James&lt;/p&gt;

</description>
			<pubDate>Wed, 06 Apr 2011 20:48:14 PDT</pubDate>
			<author>jmarcus</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4506/14650</guid>
		</item>
		<item>
			<title>splunk2nagios when Splunk and Nagios not on the same machine</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/2839/14648</link>
			<description>&lt;p&gt;bump.&lt;/p&gt;

&lt;p&gt;were you able to get this working?&lt;/p&gt;

</description>
			<pubDate>Thu, 31 Mar 2011 00:47:13 PDT</pubDate>
			<author>pchang</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/2839/14648</guid>
		</item>
		<item>
			<title>Splunk deployment services</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4504/14647</link>
			<description>&lt;p&gt;Hello,&lt;/p&gt;

&lt;p&gt;I understand that the splunk forwarder requires several local permissions on a Windows machine:&lt;/p&gt;

&lt;p&gt;Permission to log on as a service&lt;br /&gt;
permission to log on as a batch job&lt;br /&gt;
replace a process-level token&lt;br /&gt;
permission to act as an operating system&lt;br /&gt;
permission to bypass traverse checking&lt;/p&gt;

&lt;p&gt;How can these permissions can be granted across an entire domain?  A GPO is suggested as an answer however this is not feasible since a GPO will overwrite any existing local permissions on a local machine as described here:&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/1da524c5-6680-4c0a-8411-e8f243f41ea1&quot; onclick=&quot;window.open(this.href, '_blank'); return false;&quot;&gt;http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/1da524c5-6680-4c0a-8411-e8f243f41ea1&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;How have other large enterprises addressed this problem?&lt;/p&gt;

</description>
			<pubDate>Wed, 30 Mar 2011 11:40:16 PDT</pubDate>
			<author>dbutch1976</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4504/14647</guid>
		</item>
		<item>
			<title>Splunk deployment services</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4504/14639</link>
			<description>&lt;p&gt;Lol, sorry, didn't realize it was a complete doc.  Thanks.&lt;/p&gt;

</description>
			<pubDate>Tue, 22 Mar 2011 07:23:50 PDT</pubDate>
			<author>dbutch1976</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4504/14639</guid>
		</item>
		<item>
			<title>Splunk deployment services</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4504/14638</link>
			<description>&lt;p&gt;i'm a little confused--did you not read the rest of the topics in that chapter?&lt;/p&gt;

&lt;p&gt;when you load that topic, look to the left. there is a Table of Contents which shows you where you are in the manual. the topic you linked is the introduction to an entire chapter about the deployment server and how to use it.&lt;/p&gt;

</description>
			<pubDate>Mon, 21 Mar 2011 13:18:01 PDT</pubDate>
			<author>rachel</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4504/14638</guid>
		</item>
		<item>
			<title>Splunk deployment services</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4504/14637</link>
			<description>&lt;p&gt;Hello,&lt;/p&gt;

&lt;p&gt;I'm looking for some in depth information about Splunk Depoyment services.  So far I've only been able to find the following:&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://www.splunk.com/base/Documentation/4.2/Deploy/Aboutdeploymentserver&quot;&gt;http://www.splunk.com/base/Documentation/4.2/Deploy/Aboutdeploymentserver&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I'd like to get into the specifics of how I should plan to roll Splunk out, and how to perform a deployment but the link seems pretty basic.  Is there another source for more in depth info?&lt;/p&gt;

&lt;p&gt;Thanks.&lt;/p&gt;

</description>
			<pubDate>Mon, 21 Mar 2011 10:41:47 PDT</pubDate>
			<author>dbutch1976</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4504/14637</guid>
		</item>
		<item>
			<title>Convert from Trail to Free License</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4439/14630</link>
			<description>&lt;p&gt;The instructions for switching to the free license don't work if you can't get into the web interface. Like when the default password fails to work on a fresh installation. Everything else works but I can't see the web interface (just the login screen) and I can't convert the client to &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/LightForwarder&quot;&gt;LightForwarder&lt;/a&gt;.&lt;/p&gt;

</description>
			<pubDate>Tue, 15 Mar 2011 15:25:30 PDT</pubDate>
			<author>mntbighker</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4439/14630</guid>
		</item>
		<item>
			<title>change back to default value after refresh</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3942/14619</link>
			<description>&lt;p&gt;Was there a resolution on this to disable custom viewstates per user?&lt;/p&gt;

&lt;p&gt;I'm having problems where I would like to update the global viewstates via admin however this only applies changes to that individual users rather than into the default viewstate.&lt;/p&gt;

&lt;p&gt;Joshua&lt;/p&gt;

</description>
			<pubDate>Thu, 03 Mar 2011 02:31:30 PST</pubDate>
			<author>TescoDotcom</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3942/14619</guid>
		</item>
		<item>
			<title>Is it possible to show image link in front of Splunk ?</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4491/14601</link>
			<description>&lt;p&gt;I have log included image info. Is it possible to show the image link in front of Splunk's search ? tks&lt;/p&gt;

&lt;p&gt;Hudson&lt;/p&gt;

&lt;p&gt;[Revised on Sun, 13 Feb 2011 19:34:31 -0800]&lt;/p&gt;

&lt;p&gt;if there is tutorial or sample to study and it will be grateful , tks&lt;/p&gt;

</description>
			<pubDate>Sun, 13 Feb 2011 19:30:51 PST</pubDate>
			<author>hudson</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4491/14601</guid>
		</item>
		<item>
			<title>Web Service Doesnt Start</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/2892/14600</link>
			<description>&lt;p&gt;The above solution worked for me as well.  Win2008&lt;/p&gt;

&lt;p&gt;[Revised on Sun, 13 Feb 2011 13:59:19 -0800]&lt;/p&gt;

&lt;p&gt;THANKS!!&lt;/p&gt;

</description>
			<pubDate>Sun, 13 Feb 2011 13:59:04 PST</pubDate>
			<author>dwilcox</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/2892/14600</guid>
		</item>
		<item>
			<title>search for 200 hundred errors on multiple web servers with regex</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4488/14590</link>
			<description>&lt;p&gt;I'm looking to do something like ...&lt;/p&gt;

&lt;p&gt;&lt;em&gt;host=&amp;quot;web10|web9|web11&amp;quot;   sourcetype=&amp;quot;access_combined&amp;quot; status=200 |stats &lt;/em&gt;count by clientip&lt;/p&gt;

&lt;p&gt;how does one specify multiple hostnames ?&lt;/p&gt;

&lt;p&gt;Thanks.&lt;/p&gt;

</description>
			<pubDate>Mon, 31 Jan 2011 13:04:12 PST</pubDate>
			<author>sethrei</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4488/14590</guid>
		</item>
		<item>
			<title>Reference sheet for beginners</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/155/14585</link>
			<description>&lt;p&gt;yes, they are from 2006.  Splunk is now at 4.1.6. it was at 2.0 when the last post was added. if you're looking for getting started info, i recommend walking through the User Tutorial:&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://www.splunk.com/base/Documentation/latest/User/WelcometotheSplunktutorial&quot;&gt;http://www.splunk.com/base/Documentation/latest/User/WelcometotheSplunktutorial&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;there is also a cheatsheet for the search language here:&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://www.splunk.com/base/Documentation/latest/SearchReference/SearchCheatsheet&quot;&gt;http://www.splunk.com/base/Documentation/latest/SearchReference/SearchCheatsheet&lt;/a&gt;&lt;/p&gt;

</description>
			<pubDate>Wed, 26 Jan 2011 10:17:24 PST</pubDate>
			<author>rachel</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/155/14585</guid>
		</item>
		<item>
			<title>Reference sheet for beginners</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/155/14584</link>
			<description>&lt;p&gt;None of the links in this topic work.&lt;/p&gt;

</description>
			<pubDate>Mon, 24 Jan 2011 07:51:52 PST</pubDate>
			<author>Engineer88</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/155/14584</guid>
		</item>
		<item>
			<title>Howto - Use Splunk on one Linux server to analyse syslogs on remote Linux server</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4485/14582</link>
			<description>&lt;p&gt;1) i'd recommend posting this on answers.splunk.com; it supersedes this forum and is very active. you may get some better/more detailed responses than:&lt;/p&gt;

&lt;p&gt;2) have you looked into Splunk forwarders? &lt;br /&gt;
&lt;a href=&quot;http://www.splunk.com/base/Documentation/latest/Admin/Aboutforwardingandreceiving&quot;&gt;http://www.splunk.com/base/Documentation/latest/Admin/Aboutforwardingandreceiving&lt;/a&gt;&lt;br /&gt;
this allows you to install an agent on the syslog aggregation host and forward the data you want to a different server that is running a full copy of Splunk and doing the indexing. this way, not only can you keep the load off the old hardware, but you can also filter out the data you're not interested in indexing in Splunk before it hits the indexer.&lt;/p&gt;

</description>
			<pubDate>Wed, 19 Jan 2011 10:45:44 PST</pubDate>
			<author>rachel</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4485/14582</guid>
		</item>
		<item>
			<title>Howto - Use Splunk on one Linux server to analyse syslogs on remote Linux server</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4485/14581</link>
			<description>&lt;p&gt;Hi all --&lt;/p&gt;

&lt;p&gt;I've Google'ed about, and checked documentation, but I can't find exactly what I'm after here -&lt;br /&gt;
Plenty of documentation exists on how to get Splunk to analyse syslog when the syslog is +local+ to the same *nix or Windoze server&lt;/p&gt;

&lt;p&gt;I can't find some notes on how to do this:&lt;/p&gt;

&lt;p&gt;1. Splunk running on a Linux server&lt;br /&gt;
2. Syslogs coming from many hosts to a _different_ Linux server.&lt;/p&gt;

&lt;p&gt;I cannot run Splunk directly on that server running syslog, because it runs it up to 80-90% CPU, and interferes with the effectiveness of the Nagios running on that server. (Old hardware)&lt;/p&gt;

&lt;p&gt;I cannot immediately reconfigure all 200+ hosts in my network to syslog to some new address - key hardware requires a reboot in order to make the change, which affects production for users.&lt;/p&gt;

&lt;p&gt;For now, I'd like to simply get Splunk on the first Linux server to looking at the various files in  /var/log on the syslog Linux server.&lt;/p&gt;

&lt;p&gt;What am I misunderstanding about how I get Splunk to look at remote files?&lt;/p&gt;

&lt;p&gt;Same sort of question arises, for IIS/Apache files on a remote server?&lt;/p&gt;

</description>
			<pubDate>Fri, 14 Jan 2011 12:26:58 PST</pubDate>
			<author>treimers</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4485/14581</guid>
		</item>
		<item>
			<title>Why Splunk at all?</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/213/14578</link>
			<description>&lt;p&gt;I have been in the process of implementing a series of searches that have the same excludes as logwatch, so far this is a big project, but not entirely undo-able. It seems to me that the next logical step for splunk would be this. Why would I want 500 logwatch messages every day, when I could have a summary in one email?&lt;/p&gt;

</description>
			<pubDate>Fri, 14 Jan 2011 09:23:01 PST</pubDate>
			<author>mcafeesecure</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/213/14578</guid>
		</item>
		<item>
			<title>Comparing 2 events based on a common value of 2 different fields.</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4480/14571</link>
			<description>&lt;p&gt;Thanks on both counts, I had a look at diff before but it doesn't seem quite what I am looking after as I'm trying to compare 2 different events, not the same one.&lt;/p&gt;

</description>
			<pubDate>Thu, 30 Dec 2010 23:25:15 PST</pubDate>
			<author>damianshaw</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4480/14571</guid>
		</item>
		<item>
			<title>Comparing 2 events based on a common value of 2 different fields.</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4480/14570</link>
			<description>&lt;p&gt;hi damianshaw, i recommend you ask this question over at answers.splunk.com (it's much more active than this forum), but in the meantime, it's possible that the delta search command can help you accomplish what you're interested in:&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://www.splunk.com/base/Documentation/latest/SearchReference/Delta&quot;&gt;http://www.splunk.com/base/Documentation/latest/SearchReference/Delta&lt;/a&gt;&lt;/p&gt;

</description>
			<pubDate>Thu, 30 Dec 2010 16:40:56 PST</pubDate>
			<author>rachel</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4480/14570</guid>
		</item>
		<item>
			<title>Comparing 2 events based on a common value of 2 different fields.</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4480/14569</link>
			<description>&lt;p&gt;Hi,&lt;/p&gt;

&lt;p&gt;I have 2 events that have the same value for different fields, i.e I have an event with field1 and another event with field2 and value of field1 = value of field2&lt;/p&gt;

&lt;p&gt;I want to plot a graph of the difference in timestamps of events where value of field 1 = value of field 2. Is this possible?&lt;/p&gt;

</description>
			<pubDate>Thu, 30 Dec 2010 06:38:36 PST</pubDate>
			<author>damianshaw</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4480/14569</guid>
		</item>
		<item>
			<title>mySQL slow query log</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/2358/14564</link>
			<description>&lt;p&gt;Thanks for sharing...&lt;/p&gt;

</description>
			<pubDate>Wed, 22 Dec 2010 05:00:54 PST</pubDate>
			<author>missinglink</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/2358/14564</guid>
		</item>
		<item>
			<title>How to automate Splunk association/correlation of  syslog IPs with &quot;Whois&quot; info?</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3024/14556</link>
			<description>&lt;p&gt;to Splunkalicious&lt;/p&gt;

&lt;p&gt;What did you have to in Smoothwall to get the snort logs to forward to your Splunk server since there is no syslog-ng application?&lt;/p&gt;

</description>
			<pubDate>Mon, 06 Dec 2010 23:59:56 PST</pubDate>
			<author>rpetty12</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3024/14556</guid>
		</item>
		<item>
			<title>network logging</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4477/14555</link>
			<description>&lt;p&gt;Ok, I'll try it over there. Thanks for the heads up.&lt;/p&gt;

</description>
			<pubDate>Wed, 01 Dec 2010 07:42:07 PST</pubDate>
			<author>rwallace</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4477/14555</guid>
		</item>
		<item>
			<title>network logging</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4477/14553</link>
			<description>&lt;p&gt;hey there! i recommend you ask your questions over at answers.splunk.com, it's much more active than these forums.&lt;/p&gt;

</description>
			<pubDate>Tue, 30 Nov 2010 17:28:22 PST</pubDate>
			<author>rachel</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4477/14553</guid>
		</item>
		<item>
			<title>Missing events in default syslog indexing</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3515/14552</link>
			<description>&lt;p&gt;hey there! i recommend you ask your questions over at answers.splunk.com, it's much more active than these forums.&lt;/p&gt;

</description>
			<pubDate>Tue, 30 Nov 2010 17:28:01 PST</pubDate>
			<author>rachel</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3515/14552</guid>
		</item>
		<item>
			<title>Missing events in default syslog indexing</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3515/14551</link>
			<description>&lt;p&gt;Did you ever get an answer?  I have having sorta the same issue.&lt;/p&gt;

&lt;p&gt;IOerror [Errno 32] Broken pipe&lt;/p&gt;

</description>
			<pubDate>Tue, 30 Nov 2010 09:33:45 PST</pubDate>
			<author>djfisher</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3515/14551</guid>
		</item>
		<item>
			<title>network logging</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4477/14550</link>
			<description>&lt;p&gt;Hi all -&lt;/p&gt;

&lt;p&gt;I'm experiencing an issue where logging to splunk over the network (either via TCP or UDP) sometimes chunks multiple lines into the same log entry.  Is there any way to force these entries to be split as splunk receives them from the port?&lt;/p&gt;

</description>
			<pubDate>Tue, 30 Nov 2010 09:08:27 PST</pubDate>
			<author>rwallace</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4477/14550</guid>
		</item>
		<item>
			<title>Show license: Segmentation fault</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4476/14549</link>
			<description>&lt;p&gt;I use splunk with Free license and have already 3 License violations:&lt;br /&gt;
License violation #3 at Nov 18, 2010 12:04:13 AM&lt;br /&gt;
License violation #2 at Nov 14, 2010 12:00:28 AM&lt;br /&gt;
License violation #1 at Nov 10, 2010 12:02:35 AM&lt;/p&gt;

&lt;p&gt;'/opt/splunk/bin/splunk show license' shows the following info:&lt;br /&gt;
Current Daily Usage Amount:     98613194&lt;br /&gt;
Expiration date:                2037-01-20T22:30:11+0300&lt;br /&gt;
Segmentation fault&lt;/p&gt;

&lt;p&gt;What may be the cause of segmentation fault, and is there a known workaround?&lt;/p&gt;

</description>
			<pubDate>Mon, 29 Nov 2010 04:09:33 PST</pubDate>
			<author>spy</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4476/14549</guid>
		</item>
		<item>
			<title>Host monitoring</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4471/14537</link>
			<description>&lt;p&gt;Hello&lt;br /&gt;
I have just installed splunk on my work and have the firewalls and wireless stuff send syslog to it. &lt;br /&gt;
Im also looking for some monitoring of the server. Now i wonder if its best to put on something like ossec and integrate it with splunk or use splunks own tool for monitoring servers?&lt;br /&gt;
The same with nagios and have it send events with syslog to the splunk server or is splunks own tools for doing the same stuff as good?&lt;/p&gt;

</description>
			<pubDate>Sun, 07 Nov 2010 12:19:12 PST</pubDate>
			<author>fisk12</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4471/14537</guid>
		</item>
		<item>
			<title>Daily indexing volume limit exceeded</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4467/14536</link>
			<description>&lt;p&gt;I found this, might help:&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://answers.splunk.com/questions/322/what-happens-when-i-exceed-my-licensed-limit&quot; onclick=&quot;window.open(this.href, '_blank'); return false;&quot;&gt;http://answers.splunk.com/questions/322/what-happens-when-i-exceed-my-licensed-limit&lt;/a&gt;&lt;/p&gt;

</description>
			<pubDate>Fri, 05 Nov 2010 16:42:03 PDT</pubDate>
			<author>atrieger</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4467/14536</guid>
		</item>
		<item>
			<title>Daily indexing volume limit exceeded</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4467/14534</link>
			<description>&lt;p&gt;Can anyone help me?&lt;/p&gt;

</description>
			<pubDate>Wed, 03 Nov 2010 04:35:24 PDT</pubDate>
			<author>netspin</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4467/14534</guid>
		</item>
		<item>
			<title>Search by file name?</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4469/14532</link>
			<description>&lt;p&gt;As an admin that's used to searching logs with /bin/less, ? and /, I find the Splunk web interface pretty confusing.&lt;/p&gt;

&lt;p&gt;How can I limit searches in the web UI to specific source file names? In fact, I can't even see where Splunk even shows the name of the file that searches appeared in. This is really confusing. If I don't know what file a match was in, I really have no context of what I am seeing.&lt;/p&gt;

&lt;p&gt;Doug.&lt;/p&gt;

</description>
			<pubDate>Sat, 30 Oct 2010 22:11:39 PDT</pubDate>
			<author>dgarstang</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4469/14532</guid>
		</item>
		<item>
			<title>Daily indexing volume limit exceeded</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4467/14529</link>
			<description>&lt;p&gt;I install splunk with free licence and I send to it about 50 MB@day.&lt;br /&gt;
After some day I get this message on webGUI:&lt;br /&gt;
&amp;quot;Daily indexing volume limit exceeded&amp;quot;&lt;/p&gt;

&lt;p&gt;What does this mean? &lt;br /&gt;
The index limit in free version is not 500 MB@day?&lt;/p&gt;

&lt;p&gt;Thanks&lt;/p&gt;

</description>
			<pubDate>Tue, 26 Oct 2010 09:02:07 PDT</pubDate>
			<author>netspin</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4467/14529</guid>
		</item>
		<item>
			<title>rsyslog vs. syslog-ng</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4357/14527</link>
			<description>&lt;p&gt;I'm interested in what you found regarding this. I'm researching the pros/cons of using syslog/rsyslog/syslog-ng as an intermediate filter before it hits Splunk. Performance is certainly a consideration.&lt;br /&gt;
-Matt&lt;/p&gt;

</description>
			<pubDate>Mon, 25 Oct 2010 12:29:17 PDT</pubDate>
			<author>mkeys</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4357/14527</guid>
		</item>
		<item>
			<title>Bug report: Adding more than one forwarder using WEB UI</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4466/14526</link>
			<description>&lt;p&gt;Splunk 4.1.5 on Windows 2003 32bit (however don't think it's to do with the 2003 or 32 bit - possibly with windows or with WEB UI).&lt;/p&gt;

&lt;p&gt;Added a bunch of lightforwarders to our two main splunk systems... one received traffic and the other didn't.&lt;/p&gt;

&lt;p&gt;Checked and I could ping and telnet to both on port 9997 (the port we use for receiving).&lt;/p&gt;

&lt;p&gt;These errors in splunkd.log:&lt;/p&gt;

&lt;p&gt;10-22-2010 14:52:26.699 ERROR &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TcpOutputProc&quot;&gt;TcpOutputProc&lt;/a&gt; - the 'defaultGroup' property contains an invalid group name - rnln-unixmon01.teamphone.priv_9997 - skipping&lt;br /&gt;
10-22-2010 14:52:26.699 INFO  &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TcpOutputProc&quot;&gt;TcpOutputProc&lt;/a&gt; - Will retry at max backoff sleep forever&lt;br /&gt;
10-22-2010 14:52:26.699 INFO  &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TcpOutputProc&quot;&gt;TcpOutputProc&lt;/a&gt; - Using clear text for server rnln-unixmon01.teamphone.priv:9997&lt;br /&gt;
10-22-2010 14:52:26.699 INFO  &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TcpOutputProc&quot;&gt;TcpOutputProc&lt;/a&gt; - ALL Connections will use SSL with sslCipher=&lt;br /&gt;
10-22-2010 14:52:26.699 INFO  &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TcpOutputProc&quot;&gt;TcpOutputProc&lt;/a&gt; - initializing single connection with retry strategy for rnln-unixmon01.teamphone.priv:9997&lt;br /&gt;
10-22-2010 14:52:26.699 INFO  &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TcpOutputProc&quot;&gt;TcpOutputProc&lt;/a&gt; - attempting to connect to rnln-unixmon01.teamphone.priv:9997...&lt;br /&gt;
10-22-2010 14:52:26.699 INFO  &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TcpOutputProc&quot;&gt;TcpOutputProc&lt;/a&gt; - Will retry at max backoff sleep forever&lt;br /&gt;
10-22-2010 14:52:26.699 INFO  &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TcpOutputProc&quot;&gt;TcpOutputProc&lt;/a&gt; - Using clear text for server tpln-scom01.teamphone.priv:9997&lt;br /&gt;
10-22-2010 14:52:26.699 INFO  &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TcpOutputProc&quot;&gt;TcpOutputProc&lt;/a&gt; - ALL Connections will use SSL with sslCipher=&lt;br /&gt;
10-22-2010 14:52:26.699 INFO  &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TcpOutputProc&quot;&gt;TcpOutputProc&lt;/a&gt; - initializing single connection with retry strategy for tpln-scom01.teamphone.priv:9997&lt;br /&gt;
10-22-2010 14:52:26.699 INFO  &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/TcpOutputProc&quot;&gt;TcpOutputProc&lt;/a&gt; - attempting to connect to tpln-scom01.teamphone.priv:9997...&lt;br /&gt;
10-22-2010 14:52:26.699 INFO  loader - Instantiated plugin: controlqueueoutputprocessor&lt;/p&gt;

&lt;p&gt;Turned out to be that I was adding both servers on the same line separated by commas as suggested by the WEB UI help text.... as this:&lt;/p&gt;

&lt;p&gt;tpln-scom01.teamphone.priv:9997, rnln-unixmon01.teamphone.priv:9997&lt;/p&gt;

&lt;p&gt;I *think* it's because I had a space after the comma. However both servers appeared fine in the list of servers to forward to. Only by taking out the broken rnln-unixmon01 one and re-adding it by itself did it work.&lt;/p&gt;

&lt;p&gt;Now I have to go back and fix 10 of those servers - still - at least I hadn't rolled it out to the next 40. :)&lt;/p&gt;

&lt;p&gt;Will try both servers separated by comma without a space when I roll out the next one but thought I would let you know.&lt;/p&gt;

&lt;p&gt;Matt&lt;/p&gt;

</description>
			<pubDate>Fri, 22 Oct 2010 07:30:18 PDT</pubDate>
			<author>matthewhaswell</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4466/14526</guid>
		</item>
		<item>
			<title>view log file of our choosing</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4463/14522</link>
			<description>&lt;p&gt;Is it possible in splunk to&lt;/p&gt;

&lt;ul&gt;
    &lt;li&gt;View the most recent log file in its entirety&lt;/li&gt;
    &lt;li&gt;View the any log file of our choosing, in its entirety&lt;/li&gt;
    &lt;li&gt;View a comprehensive listing of all log files (filenames with complete system information such as timestamps.. etc etc)&lt;/li&gt;
&lt;/ul&gt;

</description>
			<pubDate>Mon, 18 Oct 2010 10:40:48 PDT</pubDate>
			<author>zsyed</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4463/14522</guid>
		</item>
		<item>
			<title>splunk - through proxy</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/2531/14517</link>
			<description>&lt;p&gt;Hi keithc,&lt;/p&gt;

&lt;p&gt;Can you please explain in steps what you did from scratch that overcome this problem. I am having a similar issue, we recently installed Splunk on our server which is already running our main site. I've installed splunk on port 8000 and on wordpress mu, installation seemed to work fine without any errors, but when I try to access the interface through my browser, it gives the following error:&lt;/p&gt;

&lt;p&gt;The connection has timed out&lt;/p&gt;

&lt;p&gt;The server at servername.hostname.com is taking too long to respond.&lt;/p&gt;

&lt;p&gt;*   The site could be temporarily unavailable or too busy. Try again in a few&lt;br /&gt;
          moments&lt;br /&gt;
    *   If you are unable to load any pages, check your computer's network&lt;br /&gt;
          connection&lt;br /&gt;
    *   If your computer or network is protected by a firewall or proxy, make sure&lt;br /&gt;
          that Firefox is permitted to access the Web&lt;/p&gt;

&lt;p&gt;I know its not a network issue. Any help would be appreciated,&lt;br /&gt;
thanks.&lt;/p&gt;

</description>
			<pubDate>Thu, 07 Oct 2010 08:43:06 PDT</pubDate>
			<author>khuneo</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/2531/14517</guid>
		</item>
		<item>
			<title>Oldest Windows Last Logon</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4295/14516</link>
			<description>&lt;p&gt;I am pulling Active Directory logs and am trying to figure out a way to list all user and computer objects that have logged on in a 24hr period against each DC&lt;/p&gt;

&lt;p&gt;Any ideas? Thanks.&lt;/p&gt;

</description>
			<pubDate>Wed, 06 Oct 2010 18:35:22 PDT</pubDate>
			<author>jgigliotti</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4295/14516</guid>
		</item>
		<item>
			<title>Cisco ASA: Extract Fields and count the values with rex</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4459/14513</link>
			<description>&lt;p&gt;Hallo,&lt;/p&gt;

&lt;p&gt;my Cisco ASA logs the following message:&lt;/p&gt;

&lt;p&gt;&amp;lt;172&amp;gt;Oct 05 2010 15:57:06: %ASA-4-106023: Deny tcp src outside:11.12.14.14/1193 dst inside:22.11.4.1/445 by access-group &amp;quot;outside1&amp;quot; [0x0, 0x0]&lt;/p&gt;

&lt;p&gt;I want to extract the following fields (&amp;lt;xxx&amp;gt;):&lt;/p&gt;

&lt;p&gt;&amp;lt;172&amp;gt;Oct 05 2010 15:57:06: %ASA-4-106023: Deny tcp src &amp;lt;roule&amp;gt;:&amp;lt;srcIP&amp;gt;/1193 dst inside:&amp;lt;dstIP&amp;gt;/445 by access-group &amp;quot;outside1&amp;quot; [0x0, 0x0&lt;/p&gt;

&lt;p&gt;Then i want to count the fields by:&lt;/p&gt;

&lt;p&gt;rule + srcIP + dstIP&lt;/p&gt;

&lt;p&gt;Can you help me?&lt;/p&gt;

&lt;p&gt;Thanks&lt;/p&gt;

&lt;p&gt;Thomas&lt;/p&gt;

</description>
			<pubDate>Tue, 05 Oct 2010 07:26:51 PDT</pubDate>
			<author>syslogd</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4459/14513</guid>
		</item>
		<item>
			<title>Trying to create a very simple email notification</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4458/14512</link>
			<description>&lt;p&gt;Found out how to get the results using the table command:&lt;/p&gt;

&lt;p&gt;sourcetype=&amp;quot;BITS_Billing_Logger&amp;quot; action=&amp;quot;update&amp;quot; | sort by modtime | table modtime host path uid action&lt;/p&gt;

&lt;p&gt;However the email (Outputting inline in html format) still puts the fields in whatever random order it desires.  Any help would be greatly appreciated.&lt;/p&gt;

</description>
			<pubDate>Mon, 04 Oct 2010 10:23:35 PDT</pubDate>
			<author>balt</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4458/14512</guid>
		</item>
		<item>
			<title>Trying to create a very simple email notification</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4458/14511</link>
			<description>&lt;p&gt;I am struggling with something that common sense tells me should be an incredibly simple thing to do in Splunk:  I am attempting to send the results from a saved search in an email on a 24hour basis that shows all alterations done using fs_change.&lt;/p&gt;

&lt;p&gt;The search works beautifully in the search application, however the email that is sent contains fields that I do not want and is missing fields that I do.&lt;/p&gt;

&lt;p&gt;The saved search is as follows:&lt;/p&gt;

&lt;p&gt;sourcetype=&amp;quot;BITS_Billing_Logger&amp;quot; action=&amp;quot;update&amp;quot; | Fields _date host path uid action&lt;/p&gt;

&lt;p&gt;The search reports back the information I want, however the email that is sent with the results included in the email does not contain the date, but instead the time in some god awful format.&lt;/p&gt;

&lt;p&gt;In addition instead of the fields I have specified it has the _time field as well as the _raw field, neither of which do I want in the email.&lt;/p&gt;

&lt;p&gt;My question is simple, how do I get the output results in the body of the email to only include the fields that I desire?&lt;/p&gt;

</description>
			<pubDate>Mon, 04 Oct 2010 09:34:24 PDT</pubDate>
			<author>balt</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4458/14511</guid>
		</item>
		<item>
			<title>Multi-line Windows event regex help</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/2706/14510</link>
			<description>&lt;p&gt;Any idea if &amp;quot;Service Name: krbtgt&amp;quot; is at all useful information??  We get tons of these events but are not sure what to do with them...&lt;br /&gt;
Thanks,&lt;br /&gt;
Greg&lt;/p&gt;

</description>
			<pubDate>Thu, 30 Sep 2010 15:08:41 PDT</pubDate>
			<author>gregsternyc</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/2706/14510</guid>
		</item>
		<item>
			<title>Self-guided classes</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3048/14507</link>
			<description>&lt;p&gt;I hope not&lt;/p&gt;

</description>
			<pubDate>Tue, 28 Sep 2010 22:48:06 PDT</pubDate>
			<author>gooza</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3048/14507</guid>
		</item>
		<item>
			<title>Field Extraction RegEx Help</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4453/14499</link>
			<description>&lt;p&gt;Hey guys,&lt;/p&gt;

&lt;p&gt;I'm using a &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/RegEx&quot;&gt;RegEx&lt;/a&gt; to pull out information from Cisco syslog messages from my 6500 series switches.  I'm using this &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/RegEx&quot;&gt;RegEx&lt;/a&gt; to grab the &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/SyslogSeverity&quot;&gt;SyslogSeverity&lt;/a&gt; from the message itself: (?i)%[^\-]*\-(?P&amp;lt;&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/SyslogSeverity&quot;&gt;SyslogSeverity&lt;/a&gt;&amp;gt;[0-7])(?=\-).  This works for about 95% of the messages, but occasionally, Cisco will throw a message at me that doesn't get caught because it has an extra dash in it.  Here is an example of a message that works great: %SPANTREE-2-BLOCK_BPDUGUARD.  Here is an example of a message that doesn't get caught: %EARL_NETFLOW-SP-4-TCAM_THRLD.  Note the extra dash.&lt;/p&gt;

&lt;p&gt;I just can't seem to figure out the correct &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/RegEx&quot;&gt;RegEx&lt;/a&gt; to grab both scenarios.  Any help would be greatly appreciated.&lt;/p&gt;

&lt;p&gt;Thanks,&lt;br /&gt;
Russ&lt;/p&gt;

</description>
			<pubDate>Thu, 23 Sep 2010 13:26:17 PDT</pubDate>
			<author>russuhte</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4453/14499</guid>
		</item>
		<item>
			<title>Size of sourcetype query?</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4451/14495</link>
			<description>&lt;p&gt;We had a sudden drop in events being sent to splunk. Is anyone aware of a way to query a sourcetype by size so we can see which ones stopped sending to splunk?&lt;/p&gt;

&lt;p&gt;Any help is greatly appreciated....&lt;/p&gt;

</description>
			<pubDate>Tue, 21 Sep 2010 16:58:08 PDT</pubDate>
			<author>kwaingrow</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4451/14495</guid>
		</item>
		<item>
			<title>Splunk Mailing List</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4448/14491</link>
			<description>&lt;p&gt;I just wanted to share the beginning of a Splunk mailing list, hosted by the University of Connecticut.&lt;/p&gt;

&lt;p&gt;Topics might include, but would not be limited to: sharing of crafted  searches,scripts for integrating other systems into Splunk, automation of activity upon observed event, dashboard creation, Splunk forwarder usage, highly available configuration, and other discussion regarding deployment.&lt;/p&gt;

&lt;p&gt;The mailing list is accessible for subscription at the following address:&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://listserv.uconn.edu/cgi-bin/wa?A0=SPLUNK-L&quot; onclick=&quot;window.open(this.href, '_blank'); return false;&quot;&gt;https://listserv.uconn.edu/cgi-bin/wa?A0=SPLUNK-L&lt;/a&gt;&lt;br /&gt;
Alternatively, one may subscribe by sending an email to listserv@listserv.uconn.edu containing &amp;quot;SUB SPLUNK-L &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/FirstName&quot;&gt;FirstName&lt;/a&gt; Lastname&amp;quot; in the body. No subject is required, and a signature should be omitted.  A response will be sent in return with further instructions.&lt;/p&gt;

&lt;p&gt;Please feel free to share this information with whomever else you feel might be interested. The list is just getting started, so anyone willing to join at this juncture will help get the ball rolling.&lt;/p&gt;

&lt;p&gt;-Steve&lt;/p&gt;

</description>
			<pubDate>Mon, 13 Sep 2010 09:57:30 PDT</pubDate>
			<author>smaresca</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4448/14491</guid>
		</item>
		<item>
			<title>Linux on PPC</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/499/14489</link>
			<description>&lt;p&gt;I was looking for a Splunk PPC GNU/Linux client, and this was the only information I saw.  Just thought I'd mention that I just talked to the Splunk folks and there is no Splunk PPC Linux build, so I'm guessing this is probably never gonna happen.  Just thought I'd share that in case anyone still holding onto a PPC Linux machine was curious.&lt;/p&gt;

</description>
			<pubDate>Fri, 10 Sep 2010 12:43:54 PDT</pubDate>
			<author>bmaupin</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/499/14489</guid>
		</item>
		<item>
			<title>Mysterious IIS-2 sourcetype</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4051/14488</link>
			<description>&lt;p&gt;Had similar experience.  I initially set the sourcetype to automatic for my inputs.  The data was then indexed and I ended up with sourcetype iis-2, iis-3.&lt;/p&gt;

&lt;p&gt;So I then modified the inputs.conf file to manually set the sourcetype to iis.  But my indexed data remained with iis-2 and iis-3.&lt;/p&gt;

&lt;p&gt;According to the manual, changing sourcetype affects new data coming in after the config change, and not the indexed data.&lt;/p&gt;

&lt;p&gt;So i then modified props.conf to rename the sourcetype for the already indexed data.&lt;/p&gt;

&lt;p&gt;[iis-2]&lt;br /&gt;
                  rename = iis&lt;/p&gt;

&lt;p&gt;Below is where I found it in the documentation:&lt;/p&gt;

&lt;p&gt;Override automatic source type:&lt;br /&gt;
&lt;a href=&quot;http://www.splunk.com/base/Documentation/latest/Admin/Bypassautomaticsourcetypeassignment&quot;&gt;http://www.splunk.com/base/Documentation/latest/Admin/Bypassautomaticsourcetypeassignment&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Renaming Source type:&lt;br /&gt;
 &lt;a href=&quot;http://www.splunk.com/base/Documentation/latest/Admin/Renamesourcetypes&quot;&gt;http://www.splunk.com/base/Documentation/latest/Admin/Renamesourcetypes&lt;/a&gt;&lt;/p&gt;

</description>
			<pubDate>Fri, 10 Sep 2010 08:52:57 PDT</pubDate>
			<author>choneycutt</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4051/14488</guid>
		</item>
		<item>
			<title>Self-guided classes</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3048/14482</link>
			<description>&lt;p&gt;Is the concept of self-guided classes dead?&lt;/p&gt;

</description>
			<pubDate>Thu, 02 Sep 2010 21:45:57 PDT</pubDate>
			<author>myou</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3048/14482</guid>
		</item>
		<item>
			<title>Deleted Events -- syslog</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4443/14481</link>
			<description>&lt;p&gt;I use Splunk to manage all the syslogs for my various servers.  I deleted the logs for the wrong IP address.  Is it possible for me to reinstate, reindex, or unset the delete flag in the database for the syslog entries?&lt;/p&gt;

</description>
			<pubDate>Thu, 02 Sep 2010 14:03:44 PDT</pubDate>
			<author>ejeanmaire</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4443/14481</guid>
		</item>
	</channel>
</rss>

