Getting Data In

Getting Data In
Community Activity
power12
Hey Splunkers , How can I get the splunk to use time from source and use it as _time Following are the two files it u...
by power12 Communicator in Getting Data In 04-27-2023
0 1
0
1
mloven_splunk
I have logs that are linebreaking correctly, and are single line events, but the linecount is showing as "2". I poke...
by mloven_splunk Splunk Employee Splunk Employee in Getting Data In 04-27-2023
2 4
2
4
anandhalagaras1
Hi Team, We have recently configured and ingested the Azure Active Directory Logs into Splunk. Hence we have installe...
by anandhalagaras1 Contributor in Getting Data In 04-27-2023
0 1
0
1
kanyemerch66
Hello everyone; I want to build a dashboard for specific accounts. I need to keep track of 20 reports to see if they ...
by kanyemerch66 New Member in Getting Data In 04-27-2023
0 0
0
0
nitinmp1
I have signed for the trial of splunk cloud and struggling to find how to ingest the data from AWS account. The splun...
by nitinmp1 New Member in Getting Data In 04-27-2023
0 3
0
3
Dmikos1271
I'm trying to validate if we have a large amount of data duplication. Whenever I run the dedup _raw command the numbe...
by Dmikos1271 Explorer in Getting Data In 04-27-2023
0 1
0
1
mc210274
Hello, I did some reading up on the hot, warm and cold buckets and data retention of indexes but I am not sure I 100%...
by mc210274 New Member in Getting Data In 04-26-2023
0 5
0
5
csib
Hello!We have a database that can be consulted by 4 different connection nodes.To generate high availability in the e...
by csib Engager in Getting Data In 04-26-2023
0 1
0
1
Nraj87
Easiest way to exclude ingestion of events for a specific IP address from a SourceType at UF level OR Syslog-NG ...
by Nraj87 Explorer in Getting Data In 04-26-2023
0 5
0
5
PickleRick
Trying to solve other problem, I started fiddling with outputs on my HFs and did https://www.linkedin.com/pulse/splun...
by SplunkTrust SplunkTrust in Getting Data In 04-26-2023
1 4
1
4
tretrigh
In our distributed enterprise Splunk environment we have a log file being generated on each Splunk host (indexers, se...
by tretrigh Path Finder in Getting Data In 04-25-2023
0 9
0
9
ssuluguri
Hi Team,   We have received a request to pull data from Rest API . Can you please help with any document which can he...
by ssuluguri Path Finder in Getting Data In 04-25-2023
0 1
0
1
FGo
Dear Splunk team, regarding the mentioned blog entry -- does the UF support sending to multiple destinations ("Data C...
by FGo Engager in Getting Data In 04-25-2023
0 2
0
2
Roy_9
Hello, I m trying to build the props.conf for the below log but when i am getting "failed to parse timestamp" and "de...
by Roy_9 Motivator in Getting Data In 04-25-2023
0 11
0
11
vinaykumar_aib
Good day Splunkers ,We have a Data flow coming from the source A to Kakfa Topic. Splunk Connector on the kafka using ...
by vinaykumar_aib Observer in Getting Data In 04-25-2023
0 3
0
3
remy06
I may have missed out somewhere but I'm wondering if anyone has a way to detect if splunkd is being shutdown by an ad...
by remy06 Contributor in Getting Data In 04-24-2023
0 12
0
12
hagjos43
In a test environment (two indexers, one SH, one cluster master/deployment server) I froze any data that was older th...
by hagjos43 Contributor in Getting Data In 04-24-2023
0 7
0
7
santosh_hb
Hi All, Need a quick help on creating duplicate source types in Splunk. Currently, the data is flowing into index=t...
by santosh_hb Explorer in Getting Data In 04-24-2023
0 9
0
9
bhsakarchourasi
Hi All, we are unable to see the indexers internal logs in _internal index, except mongodb logs. we verified that the...
by bhsakarchourasi Path Finder in Getting Data In 04-24-2023
0 4
0
4
nbonner
I am having issues configuring Splunk to Index NetApp CIFS logs in XML format. Here is an example of 3 events: <Eve...
by nbonner Explorer in Getting Data In 04-24-2023
0 12
0
12
CMSchelin
I have events like so:     {"action": {"result": true, "type": "login"}, "actor": {"email": "test.email@domain.tld", ...
by CMSchelin Path Finder in Getting Data In 04-23-2023
0 0
0
0
Sekhar
My query index= nonjVs source = nonjavs | stats vaules(_time ) as start time values(_time) as endtime by empid  Displ...
by Sekhar Explorer in Getting Data In 04-23-2023
0 2
0
2
JGP
If there is no file update for a quite long time and later then is update in the file, then only after forwarder serv...
by JGP Explorer in Getting Data In 04-21-2023
0 7
0
7
lukessi
Hi, I am routing traffic to a 3rd party. I have done some of this based on a host and others based on the source typ...
by lukessi Path Finder in Getting Data In 04-21-2023
0 3
0
3
sarashafek
Hi,I have a zscaler NSS connected to splunk. I've been running some tests to see how splunk reacts to change in DNS e...
by sarashafek Explorer in Getting Data In 04-20-2023
0 3
0
3
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...