Getting Data In

Getting Data In
Community Activity
0xAli
Hi Everyone,Anyone integrated the Forcepoint DLP with splunk? What is the proper method? is there any Add-on FP DLP?
by 0xAli Explorer in Getting Data In yesterday
0 3
0
3
pdominicb
I am about to have a few UFs monitoring some extremely high volume logs. These high volume logs are less critical tha...
by pdominicb Explorer in Getting Data In Sunday
0 8
0
8
pdominicb
I have events with URLs, and the URLs contain parameters with KV values in them. Splunk auto extracts the KV pairs, b...
by pdominicb Explorer in Getting Data In Friday
0 10
0
10
loganallen
I am trying to implement a postfilter in Splunk Connect for Syslog to drop east-west (internal-to-internal) Fortigate...
by loganallen Loves-to-Learn in Getting Data In Wednesday
0 0
0
0
Karthikeya
We have to pull logs from Tencent COS (Cloud Object Storage) to our Splunk instances which are hosted on AWS. Tencent...
by Karthikeya Communicator in Getting Data In a week ago
0 7
0
7
volly
iv just created a new account.iv have admin role assigned to my user account iv given admin role all permissions, yet...
by volly New Member in Getting Data In a week ago
0 2
0
2
spl_aficionado
We recently found out that we couldn't send TCP data as Syslog because it didn't have the proper header, but streamin...
by spl_aficionado Path Finder in Getting Data In 2 weeks ago
0 4
0
4
wellsjp
We use HEC to ingest data from multiple sources but are starting to see the requirement for OAuth and other security ...
by wellsjp Loves-to-Learn Lots in Getting Data In 2 weeks ago
0 5
0
5
arthy-velusamy
We are trying to ingest JSON data to Splunk Ingest Processor. Sometimes JSON data is getting ingested properly and ma...
by arthy-velusamy Observer in Getting Data In 2 weeks ago
0 1
0
1
jni
Hi,I'm ingesting journald logdata, and would like to exclude all rows with "apparmor=ALLOW".To me, the journald-filte...
by jni Explorer in Getting Data In 2 weeks ago
0 7
0
7
0xAli
Hi Everyone,While using Syslog-NG to monitor network traffic and write it into file,  I want to ask about the Log fil...
by 0xAli Explorer in Getting Data In 2 weeks ago
0 6
0
6
gitau_gm
I am observing inconsistent forwarding of Windows Security Event ID 4624 (Successful Logon) from multiple Windows hos...
by gitau_gm Explorer in Getting Data In 3 weeks ago
0 9
0
9
Hemant0808
PCAP Data contains media and audio file, Is it possible that can be converted to other format and ingest in splunk
by Hemant0808 New Member in Getting Data In 3 weeks ago
0 0
0
0
0xAli
Hi All,I hope all is well.Kindly, anyone works with Guardium API Add-on for Splunk:https://splunkbase.splunk.com/app/...
by 0xAli Explorer in Getting Data In 3 weeks ago
0 0
0
0
kvm
Hi,I'm required to integrate the Alogsec  Security Management Suite (ASMS) logs via API method to cover the richer vi...
by kvm Explorer in Getting Data In 3 weeks ago
0 3
0
3
zapping575
One of my sourcetypes is a CSV file (with CSV header)I was using this sourcetype stanza in props.conf:[foo_bar] INDEX...
by zapping575 Communicator in Getting Data In a month ago
0 1
0
1
BluFalcon
I was wondering if any one has successfully onboard KnowBe4 data? I don't see a TA or App on Splunkbase.
by BluFalcon Engager in Getting Data In a month ago
0 8
0
8
gnagasri
Sample events - working in regex101 : https://regex101.com/r/LuC6ZQ/1| rex field=_raw "nsssvcip\=(?<host>\d+\.\d+\.\d...
by gnagasri Engager in Getting Data In a month ago
0 4
0
4
Rafaelled
Good Afternoon,I have been at war with the estreamer app for 2 weeks and I can not get this to work. Below is the cur...
by Rafaelled Explorer in Getting Data In 04-24-2026
1 1
1
1
becksyboy1
Hi All,Has anyone tried to ingest Claude OpenTelemetry logs into Splunk? I'd be interested in understanding what appr...
by becksyboy1 Engager in Getting Data In 04-24-2026
0 4
0
4
Solitus31
Hello,we are trying to use splunk_app_uf_remote_upgrade_windows to upgrade our UF using Deployment server.I have inst...
by Solitus31 Explorer in Getting Data In 04-20-2026
0 2
0
2
Kat7
Hello, I would like to automatically send the audit logs from PDQ Connect into our Splunk environment.  I can manuall...
by Kat7 Explorer in Getting Data In 04-19-2026
0 3
0
3
ljo4497
Hi, We currently have a centralized WEF collection server that collects all windows logs across the environment.This ...
by ljo4497 Explorer in Getting Data In 04-15-2026
1 9
1
9
duesser
I have data of the following structure in Kafka.{"id": "ABC", "name": "lukas", "timestamp": 1775567475, "payload": 37...
by duesser Path Finder in Getting Data In 04-12-2026
0 7
0
7
durnan13
Hello Everyone!We have what we have been told is not a complete ideal setup where we have searchable data for 90 days...
by durnan13 Explorer in Getting Data In 04-11-2026
0 11
0
11
Get Updates on the Splunk Community!

Mile High Learning with Splunk University, Denver, Colorado

If Denver is known for its mile-high elevation, Splunk University is about to raise the bar on technical ...

IT Service Intelligence 5.0 Series: Your Guide to the June Launch

We are excited to announce the June release of Splunk IT Service Intelligence (ITSI) 5.0. This update ...

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...
Top Solution Authors