TIPS & TRICKS

SplunkTalk – #37 – Dude, check this out!

Episode 37 features a little Texas fireside chat. Maverick and Wilde covered the new license management in Splunk–which might seem like the most boring thing in the world–but is actually pretty cool and very capable! W’eve found some issues with figureing out what your indexing volume is when evaluating Splunk. Wilde has an interesting story about some ugly Microsoft.NET logs that have “literal newline characters” written in to the event in text and how to use the LINE_BREAKER directive in props.conf to solve this. Guess What? Splunk’s User Conference 2011 is comin up, so get registered for that, and the ninja answers a listener question about “Where did this Splunk Ninja thing come from”

Episodes are recorded live every Friday at 11AM Central Time – Email us at splunktalk@splunk.com to ask questions and have them answered on air!!

Enjoy Listening!

----------------------------------------------------
Thanks!
Michael Wilde

Splunk
Posted by

Splunk

Join the Discussion