Getting Data In

Getting Data In
Community Activity
Dan
We are having an issue where we would like to route all events from a specific source to a third-party (ArcSight) but...
by Dan Splunk Employee Splunk Employee in Getting Data In 09-13-2010
1 1
1
1
briguy
Hi All - I'm using the WMI input to gather some custom WMI data. Some of the queries (such as below) result in duplic...
by briguy Engager in Getting Data In 09-13-2010
0 2
0
2
Erik_Swan
I remember reading somewhere i could do this but cannot find any docs on it. I have a scripted input that wants to p...
by Erik_Swan Splunk Employee Splunk Employee in Getting Data In 09-12-2010
2 4
2
4
fcastano
How do I force splunk to index new files in the directory that is being monitored immediately? sometimes it takes re...
by fcastano Engager in Getting Data In 09-11-2010
2 3
2
3
hulahoop
Would someone kindly confirm if Splunk is expected to preserve the order of events as they are presented in the origi...
by hulahoop Splunk Employee Splunk Employee in Getting Data In 09-10-2010
3 7
3
7
kmille2
Can the forwarding port be set to a UDP port? Tried changing the type to UDP in the outputs.conf file, but Splunk ke...
by kmille2 Explorer in Getting Data In 09-10-2010
1 2
1
2
mfrost8
I have a tree of files that looks something like the following: /var/log/able/access.log /var/log/baker/access.log /...
by mfrost8 Builder in Getting Data In 09-10-2010
0 8
0
8
kholleran
Hello, My splunk server belongs to a different domain with a trust set up. I have a python script that does some Ac...
by kholleran Communicator in Getting Data In 09-10-2010
0 7
0
7
hexx
The UI is displaying the time stamp of my events in US format (MM/DD/YYYY), but I would like the time format to be di...
by hexx Splunk Employee Splunk Employee in Getting Data In 09-09-2010
5 2
5
2
Eli_Klein
I'm having some trouble getting this working. I've tried both the regular forwarder as well as the light forwarder. ...
by Eli_Klein Explorer in Getting Data In 09-09-2010
0 2
0
2
clyde772
Any gurus know why there are files created in /var/tmp/ folder by Splunk? splunk@splunk:/var/tmp> more ddtb553596446...
by clyde772 Communicator in Getting Data In 09-09-2010
0 2
0
2
Branden
The amount of data I index daily is pretty consistent for the most part. I suppose it's gradually increasing, but no ...
by Branden Builder in Getting Data In 09-09-2010
3 5
3
5
rcshield
I am just getting started with splunk. I imported a log file from my web server. however, the file dosn't show up in ...
by rcshield New Member in Getting Data In 09-08-2010
0 1
0
1
splukUP
I have a log file that was |delete'd from the index using search. I want the file back in the index. I did several ...
by splukUP Engager in Getting Data In 09-08-2010
1 1
1
1
Simeon
I am indexing apache logs and have them rotating on a frequent basis. The log rotation will rename the file to error...
by Simeon Splunk Employee Splunk Employee in Getting Data In 09-08-2010
1 2
1
2
Alan_Bradley
We plan to use Splunk to keep log for several java application including web server like Tomcat. Those application ar...
by Alan_Bradley Path Finder in Getting Data In 09-08-2010
3 4
3
4
Brian_Osburn
We're expanding our Splunk environment from a single indexer machine that does everything, to an environment that has...
by Brian_Osburn Builder in Getting Data In 09-08-2010
10 5
10
5
digihax
I've set up Snare on remote servers to forward syslog events on port 6161 to my Splunk server. I've run wireshark on...
by digihax New Member in Getting Data In 09-08-2010
0 7
0
7
keithosullivan
I have checkpoint logs going back which we have exported of our checkpoint FW, and i would like to import them into s...
by keithosullivan New Member in Getting Data In 09-07-2010
0 4
0
4
jjackson81281
I cannot find any info to get this to work. I am running splunk on a windows vm I want to gather syslog info from the...
by jjackson81281 New Member in Getting Data In 09-07-2010
0 2
0
2
Branden
I'm having what appears to be a logic problem, but it could be something else. I have an app that displays the outpu...
by Branden Builder in Getting Data In 09-07-2010
1 16
1
16
ford1863
I have configured remote WMI in my Splunk to see the eventlogs on Windows servers. But when I index and search the ev...
by ford1863 New Member in Getting Data In 09-07-2010
0 1
0
1
LauMat
Hello, We are a consulting firm and I am assessing the Splunk solution for one of my customer. The LEA applicatio...
by LauMat Engager in Getting Data In 09-07-2010
1 3
1
3
jstillwell
I'm trying to read some config files into splunk, ala change management. I'm not using fschange, I'm using a tcp moni...
by jstillwell Explorer in Getting Data In 09-05-2010
0 5
0
5
southeringtonp
What's the best approach to start profiling a standalone server to determine either: a) the best way to improve perf...
by southeringtonp Motivator in Getting Data In 09-04-2010
1 2
1
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...