Getting Data In

Getting Data In
Community Activity
nbonner
I am having issues configuring Splunk to Index NetApp CIFS logs in XML format. Here is an example of 3 events: <Eve...
by nbonner Explorer in Getting Data In 04-24-2023
0 12
0
12
CMSchelin
I have events like so:     {"action": {"result": true, "type": "login"}, "actor": {"email": "test.email@domain.tld", ...
by CMSchelin Path Finder in Getting Data In 04-23-2023
0 0
0
0
Sekhar
My query index= nonjVs source = nonjavs | stats vaules(_time ) as start time values(_time) as endtime by empid  Displ...
by Sekhar Explorer in Getting Data In 04-23-2023
0 2
0
2
JGP
If there is no file update for a quite long time and later then is update in the file, then only after forwarder serv...
by JGP Explorer in Getting Data In 04-21-2023
0 7
0
7
lukessi
Hi, I am routing traffic to a 3rd party. I have done some of this based on a host and others based on the source typ...
by lukessi Path Finder in Getting Data In 04-21-2023
0 3
0
3
sarashafek
Hi,I have a zscaler NSS connected to splunk. I've been running some tests to see how splunk reacts to change in DNS e...
by sarashafek Explorer in Getting Data In 04-20-2023
0 3
0
3
vinoth_raj
Hi folks,   Can I delete the data in a virtual index like "Hadoop" using the delete command in the SPL.   Thanks, in ...
by vinoth_raj Path Finder in Getting Data In 04-20-2023
0 0
0
0
bowesmana
Is it an omission that the latest Windows TA will only extract registry_path if the registry_type field contains "\w+...
by SplunkTrust SplunkTrust in Getting Data In 04-19-2023
0 0
0
0
TheSteveBennett
I am able to sync my data from the Cisco managed S3 bucket to a local folder on my heavy forwarder.  The files are co...
by TheSteveBennett Observer in Getting Data In 04-19-2023
0 0
0
0
hrawat
With INDEXED_EXTRACTIONS=JSON, indexed extraction is not working if json HEC  event payload is more than 512KB.  
by hrawat Splunk Employee Splunk Employee in Getting Data In 04-19-2023
0 1
0
1
splunkcol
Hi, I currently have an outdated version of DBConnect and need to go through the upgrade process.I have several quest...
by splunkcol Builder in Getting Data In 04-18-2023
0 2
0
2
aydinmo
Hi all,I have a large environment to deploy Splunk cloud and trying to leverage the syslog server (Rsyslog) in front ...
by aydinmo Explorer in Getting Data In 04-18-2023
0 1
0
1
rgchandrasekara
If the file size in GB's would create any issue in indexing performance?
by rgchandrasekara Observer in Getting Data In 04-18-2023
0 7
0
7
omuelle1
Good morning, I am having an issue on-boarding our main Eventhub into the Splunk Add-On for Cloud Services (latest ve...
by omuelle1 Communicator in Getting Data In 04-18-2023
0 1
0
1
dhearn1920
Is it possible to send logs to S3 from a heavy forwarder?  I have seen information about being able to ingest from S3...
by dhearn1920 New Member in Getting Data In 04-18-2023
0 1
0
1
Dallastek1
WE have ALOT of aws instances with universal forwarders sending winevent logs and some are sending logs to an on prem...
by Dallastek1 Path Finder in Getting Data In 04-18-2023
0 2
0
2
mux
I need to update ownership of searches after converting to a search head cluster environmen,t and from my understandi...
by mux Explorer in Getting Data In 04-18-2023
0 3
0
3
thisissplunk
I need to do the equivalent of this: https://oursplnkserver.com/en-GB/debug/refresh?entity=admin/conf-inputs befor...
by thisissplunk Builder in Getting Data In 04-18-2023
0 5
0
5
sarashafek
Hi,I have a Zscaler NSS connected to splunk. I made a change in the dns entries so that my em1 (interface that is con...
by sarashafek Explorer in Getting Data In 04-18-2023
0 0
0
0
muradgh
Hi Splunkers, I'm trying to troubleshoot an issue with Splunk that I'm facing:I have a Splunk heavy forwarder setting...
by muradgh Path Finder in Getting Data In 04-17-2023
0 8
0
8
Pavan0604
Hi we are using aws cloud to run and maintain our infrastructure. So now we are using splunk indexer in log configura...
by Pavan0604 Loves-to-Learn in Getting Data In 04-17-2023
0 0
0
0
juju
I installed Splunk standalone with https://splunk.github.io/splunk-ansible/Version 9.0.4 on Ubuntu jammy 22.04.2 Inst...
by juju Explorer in Getting Data In 04-17-2023
0 4
0
4
SplunkExplorer
Hi Splunkers,my colleague and I are going to perform, this week, a change to forward data from Splunk HF to a third p...
by SplunkExplorer Contributor in Getting Data In 04-17-2023
0 0
0
0
sanaa
Hi , I am pretty much new to Splunk. I want to forward audit.log of one of my Linux servers to view in Splunk Web. F...
by sanaa New Member in Getting Data In 04-16-2023
0 5
0
5
icewolf69
Hi all,  I'm trying to do something that seems pretty easy conceptually.  I'm ingesting a .txt report into Splunk and...
by icewolf69 Loves-to-Learn Everything in Getting Data In 04-15-2023
0 5
0
5
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...