Getting Data In

Getting Data In
Community Activity
parallaxed
We have a configuration that's been idling for over two days, and instead of processing locations that the tailing pr...
by parallaxed Path Finder in Getting Data In 09-20-2010
2 14
2
14
iokoluke
Hello, We are looking at deploying splunk for our application servers log files, these log files are about 3GB per d...
by iokoluke New Member in Getting Data In 09-17-2010
0 2
0
2
muebel
I have splunk set up on a few redhat boxes, and I am getting duplicate events from them. One event will list the hos...
by SplunkTrust SplunkTrust in Getting Data In 09-17-2010
0 2
0
2
pde
I have records that consist of fairly large (200+ lines, > 20 Kb per record) XML documents. When I export the result...
by pde Path Finder in Getting Data In 09-17-2010
0 2
0
2
ultra
Hi, I'm new to splunk, so my question might be lame. I am trying to setup a splunk lightweight forwarder, my problem ...
by ultra Explorer in Getting Data In 09-17-2010
0 1
0
1
Caio_Santos
One Splunk instance is forwarding data to a receiver, however the receiver is indexing the data and getting the wrong...
by Caio_Santos Path Finder in Getting Data In 09-16-2010
0 2
0
2
tedder
So I have the following in inputs.conf: [udp://10005] connection_host = index = serverlogs sourcetype = syslog disab...
by tedder Communicator in Getting Data In 09-16-2010
0 3
0
3
Caio_Santos
I'm forwarding data from a windows splunk instance to a freebsd. I checked the index that i'm forwarding data to, so ...
by Caio_Santos Path Finder in Getting Data In 09-15-2010
0 1
0
1
dleung
I am checking out a sample application where an eventtype's search contains "sourcetype=..." . I having difficulty d...
by dleung Splunk Employee Splunk Employee in Getting Data In 09-14-2010
1 4
1
4
Caio_Santos
How do I know which index forwarded data goes to receiver instance ? I'm not sure about that, but i've created 2 inde...
by Caio_Santos Path Finder in Getting Data In 09-14-2010
1 2
1
2
devilears
How do I monitor how often my users are using Splunk?
by devilears New Member in Getting Data In 09-14-2010
0 1
0
1
Ant1D
Good Morning, I have a question that I would love to be answered if possible.  I have written the following xml c...
by Ant1D Motivator in Getting Data In 09-14-2010
0 11
0
11
melonman
Hi there, I would like to know how to handle international character code in Splunk. The environment I have here i...
by melonman Motivator in Getting Data In 09-14-2010
0 6
0
6
chjpcert
I've been testing Splunk for several months now, and am consistently having problems with duplicate events appearing ...
by chjpcert Explorer in Getting Data In 09-14-2010
1 8
1
8
rgcox1
So we know about lost forwarders, but how about lost logs? I recently discovered that some of my Windows systems were...
by rgcox1 Communicator in Getting Data In 09-13-2010
0 4
0
4
Nicholas_Key
Hi all, I have the following output from a Perl script that runs every 5 mins: 09-13-2010 16:21:20 - Inventory Rep...
by Nicholas_Key Splunk Employee Splunk Employee in Getting Data In 09-13-2010
1 2
1
2
SK110176
I'm noticed tons of duplicate events and the following message in splunkd.log correlates with the time I started seei...
by SK110176 Path Finder in Getting Data In 09-13-2010
1 1
1
1
Caio_Santos
Hey everybody, I'm going through some problems trying to set my receiver splunk instance. I performed exactely the w...
by Caio_Santos Path Finder in Getting Data In 09-13-2010
1 2
1
2
Genti
Folks, Im trying to troubleshoot an issue where syslog data seems to stop for a couple of days, then pick up again. ...
by Genti Splunk Employee Splunk Employee in Getting Data In 09-13-2010
1 6
1
6
skippylou
Going through other splunk answers questions I couldn't get anything that I think should be working to work here. Es...
by skippylou Communicator in Getting Data In 09-13-2010
0 8
0
8
cookdg
i downloaded the following logs to my workstation running xp and i have splunk running on it. how do i import them i...
by cookdg New Member in Getting Data In 09-13-2010
0 3
0
3
hiddenkirby
At a high level... how would one filter the content itself being indexed. Example: i was indexing ..say.. xml docs ...
by hiddenkirby Contributor in Getting Data In 09-13-2010
2 1
2
1
Dan
We are having an issue where we would like to route all events from a specific source to a third-party (ArcSight) but...
by Dan Splunk Employee Splunk Employee in Getting Data In 09-13-2010
1 1
1
1
briguy
Hi All - I'm using the WMI input to gather some custom WMI data. Some of the queries (such as below) result in duplic...
by briguy Engager in Getting Data In 09-13-2010
0 2
0
2
Erik_Swan
I remember reading somewhere i could do this but cannot find any docs on it. I have a scripted input that wants to p...
by Erik_Swan Splunk Employee Splunk Employee in Getting Data In 09-12-2010
2 4
2
4
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...
Top Solution Authors