Getting Data In

Getting Data In
Community Activity
Voltaire
Is it possible to monitor a log file from a Linux system that is not configured as a LWF? I configured the Data Inp...
by Voltaire Communicator in Getting Data In 01-18-2011
0 4
0
4
CerielTjuh
Hi there, I have noticed a difference in format between the csv files generated by Splunk when e-mail the results or...
by CerielTjuh Path Finder in Getting Data In 01-18-2011
2 1
2
1
digitalcjc
I noticed a discussion about AIX ver 6 support earlier in the year, however the website still limits the support to 5...
by digitalcjc New Member in Getting Data In 01-14-2011
0 3
0
3
Derek
Hi, I have a log file that when ingested using a one shot, all but 3 of the events get stamped with the correct date...
by Derek Path Finder in Getting Data In 01-14-2011
0 6
0
6
VictorHK
We setup Splunk to monitor log files and generate alerts on abnormal situations. Log files are recording all activit...
by VictorHK New Member in Getting Data In 01-14-2011
0 1
0
1
SamChang
Dear Sir Our customer export results to csv file. They open this csv file with Microsoft Excel. Because csv file in...
by SamChang Path Finder in Getting Data In 01-14-2011
0 7
0
7
ericmoss
How do I add data (system logs, event logs, etc) from a Linux computer (forwarder) system to a Windows System (receiv...
by ericmoss Explorer in Getting Data In 01-13-2011
0 3
0
3
Chris_Olson
Looking for some guidance on non-standard date/time parsing… We have a customer that has logs without years We're g...
by Chris_Olson Splunk Employee Splunk Employee in Getting Data In 01-13-2011
0 1
0
1
sgramenopoulos
Due to our strict security policies I need to show a security representative that Splunk can not only index windows e...
by sgramenopoulos Explorer in Getting Data In 01-13-2011
0 1
0
1
ITSD
I'd already use "| delete" try to delete host, but it still remain there with event count 0. How could I remove no mo...
by ITSD Explorer in Getting Data In 01-13-2011
0 2
0
2
clyde772
How can I define manually force define the date and time. Splunk didn't properly processes the correct time in the e...
by clyde772 Communicator in Getting Data In 01-12-2011
0 3
0
3
Jason
In inputs.conf, is a fschange stanza itself allowed to have wildcards (like monitors can, or props.conf stanzas can)?...
by Jason Motivator in Getting Data In 01-12-2011
0 3
0
3
thepocketwade
I'm trying to test some things with my Splunk Windows installs and I'd like to have reliable test data. When I test ...
by thepocketwade Path Finder in Getting Data In 01-12-2011
0 3
0
3
wang
I need to filter out certain unwanted events and send them to the nullQueue. I added this in props.conf: [access_lo...
by wang Path Finder in Getting Data In 01-12-2011
0 2
0
2
gpburgett
We've got Splunk running at a customer site and one of the things that they want is to be able to get regular statist...
by gpburgett Splunk Employee Splunk Employee in Getting Data In 01-12-2011
1 1
1
1
mbrunetto
I have a unix light forwarder that works fine for the normal default splunk forwarding (the scripts for CPU, ports, e...
by mbrunetto Path Finder in Getting Data In 01-11-2011
1 1
1
1
twinspop
I wrote a simple, REST-based proxy to query Splunk's REST API from SiteScope. The proxy manages job creation, trackin...
by twinspop Influencer in Getting Data In 01-11-2011
0 4
0
4
sgramenopoulos
Below is my indexes.conf file: defaultDatabase = main [main] homePath= $SPLUNK_DB\defaultdb\db coldPath = $SPLUNK_...
by sgramenopoulos Explorer in Getting Data In 01-10-2011
1 6
1
6
twinspop
If I run this search through the web interface: error | stats count by host | sort - count And then venture over t...
by twinspop Influencer in Getting Data In 01-10-2011
0 1
0
1
opsi
Hi All, here is what my logs look likes : 17:31:52.872 CALL(IP) (00:62582:01) Fax Mode is Bypass, Modem Mode is By...
by opsi New Member in Getting Data In 01-10-2011
0 2
0
2
Curt_Collins
Hi all, Is there a way to "nice" a scripted input process so that it doesn't swamp the CPU? I have a scripted input...
by Curt_Collins Splunk Employee Splunk Employee in Getting Data In 01-09-2011
2 2
2
2
nnachefski
Is it possible to stream results with the REST API? Every search i submit has the 'resultIsStreaming' value set to 0...
by nnachefski Engager in Getting Data In 01-07-2011
1 1
1
1
charliesullivan
Referring to http://www.splunk.com/base/Documentation/latest/admin/Aboutforwardingandreceiving, under the section "In...
by charliesullivan Engager in Getting Data In 01-07-2011
2 1
2
1
JeanD
I am trying to debug a loadData.sh scripts, and I do not see output added to Splunk. What is the best way to debug i...
by JeanD Engager in Getting Data In 01-07-2011
4 1
4
1
jambajuice
I'm trying to clean up events from a Nessus 4 NBE file. Sample results look like the following: results|192.168.2|1...
by jambajuice Communicator in Getting Data In 01-07-2011
0 2
0
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...
Top Solution Authors