splunkninja

The dojo of Splunk. Learn, share, teach, mentor.

Ferry Leirissa
  • Male
  • Rotterdam The Netherlands
  • Netherlands
Share
Share on Twitter
Share on Facebook
 

Ferry Leirissa's Page

Gifts Received

Gift

Ferry Leirissa has not received any gifts yet

Give Ferry Leirissa a Gift

Latest Activity

Hai Micheal, Whats the total input here, can you sent me it as well? Cause you dont have the fields decribed here now right? What is your advice, to do FORMAT or inline? Cheers Ferry
April 6
Hai James, This is syslog right? I am happy to help you, can you sent me a part of the logile? So I have some mass data to doublecheck before twaeking afterwards. Please sent it to leirissa@hotmail.com Thanks Ferry
April 5
Oops paste errors.... * | rex "v630\/(?P\d+\.\d+\.\d+\.\d+)" then you get the IP as a field,,hope this helps! Cheers Ferry
March 17
Hai Patrick, Guest you have to dig into the pre and postfix part : (?i) accepted: (?P.*) means : search for accepted: and put everyting .* after that in FIELDNAME Thist wil not work for the other example....based on that info you have to use someh…
March 17
Yes its possible, you can read it on http://www.splunk.com/support/forum:SplunkAdministration/3994 You have to edit the props and transforms (on receive) like : props.conf [host::devhost*] TRANSFORMS-dev = IndexIs-dev [host::prodhost*] TRANSFORMS…
March 17
Ferry Leirissa updated their profile
March 14
Ferry Leirissa updated their profile photo
March 14
Ferry Leirissa is now a member of splunkninja
March 14

Profile Information

Are you an existing splunk user?
Licensed
What do you do for your day job?
Consultant

Comment Wall

You need to be a member of splunkninja to add comments!

Join splunkninja

  • No comments yet!
 
 
 

Latest Splunk Community Postings

Loading feed

Latest Splunk Forum Posts

Loading feed

© 2010   Created by Michael Wilde.   Powered by .

Badges  |  Report an Issue  |  Terms of Service

Sign in to chat!