splunkninja

The dojo of Splunk. Learn, share, teach, mentor.

nick fox
  • london
  • United Kingdom
Share
Share on Twitter
Share on Facebook

nick fox's Discussions

splunk errors - splunk-optimize failed to start

is this anything serious to worry about? and does it impact me in any way?cheers

Started Feb 13

segmentation and text/XML files
9 Replies

Hi I have just started implementing splunk for some of our application logging and while most logs seem to be working well we have a small issue with some XML messages. I say messages because the XM…

Tagged: rpc, xml, segmentation

Started this discussion. Last reply by Bob Munson Jan 24.

 

nick fox's Page

Gifts Received

Gift

nick fox has not received any gifts yet

Give nick fox a Gift

Latest Activity

nick fox added a discussion
is this anything serious to worry about? and does it impact me in any way?cheers
February 13
When you create an index, you may not have noticed but splunk tells you to restart at the top of the screen so you did exactly what you needed to.
January 24
This works fantastic, thanks very much. on another note, It seems that when i create a new index and then go to data inputs even though i can select the index i created in the drop down i cannot save, i get an error at the top saying index not reco…
November 10, 2009
You should be cool doing this: 1. Manually Sourcetype your input. I called mine "myxml". (this can be done at the GUI when you monitor the directory, or in the $SPLUNK_HOME/etc/apps/search/local/inputs.conf file. Mine looks like this: 2. Configu…
November 7, 2009
good question. the first message is not timestamped on recipt so if there is a delay in transmission from the other side that first xml message may be inaccurate. i think the timestamp in the second message where we are forwarding it is the best, t…
November 6, 2009
More helpful than Splunk?.. well. that is why i started this community, because i think it could be far better than the Splunk forums (which are buried), and possibly better than the best practices in the docs.... but yes.. I do work for Splunk.. Fi…
November 6, 2009
wow ur more helpful than splunk! you dont work for splunk do you? Hmm good question. it might be useful in the long run to have each xml message indexed, for reporting etc but for now it would be great to just index the whole file, and maybe later…
November 6, 2009
Ok.. one more simple question... ultimately it seems like you'd just like each of these files indexed.. preferrably with a proper sourcetype. Would you like the file as one event... or the responses split up in to single events? and which field con…
November 5, 2009
ok so format is as follows: text on line 1, a cert id then xml followed by captured response xml and then duplicated again for the transmission, thats subject to change if unable to respond due to system being down etc.. (the line of hyphens are not…
November 5, 2009
Couple o' Questions for ya! Is each file a message? Is there a timestamp in the message? Is the created date on the file the time the event occured? What sourcetype is splunk assigning when it indexes the files?
November 5, 2009
nick fox added a discussion
Hi I have just started implementing splunk for some of our application logging and while most logs seem to be working well we have a small issue with some XML messages. I say messages because the XML-RPC for a particular system is logged in individ…
November 4, 2009
nick fox is now a member of splunkninja
November 4, 2009

Profile Information

Are you an existing splunk user?
Free
What do you do for your day job?
applications analyst

Comment Wall

You need to be a member of splunkninja to add comments!

Join splunkninja

  • No comments yet!
 
 
 

© 2010   Created by Michael Wilde.   Powered by .

Badges  |  Report an Issue  |  Terms of Service

Sign in to chat!