Getting Data In

Getting Data In
Community Activity
Caio_Santos
One Splunk instance is forwarding data to a receiver, however the receiver is indexing the data and getting the wrong...
by Caio_Santos Path Finder in Getting Data In 09-16-2010
0 2
0
2
tedder
So I have the following in inputs.conf: [udp://10005] connection_host = index = serverlogs sourcetype = syslog disab...
by tedder Communicator in Getting Data In 09-16-2010
0 3
0
3
Caio_Santos
I'm forwarding data from a windows splunk instance to a freebsd. I checked the index that i'm forwarding data to, so ...
by Caio_Santos Path Finder in Getting Data In 09-15-2010
0 1
0
1
dleung
I am checking out a sample application where an eventtype's search contains "sourcetype=..." . I having difficulty d...
by dleung Splunk Employee Splunk Employee in Getting Data In 09-14-2010
1 4
1
4
Caio_Santos
How do I know which index forwarded data goes to receiver instance ? I'm not sure about that, but i've created 2 inde...
by Caio_Santos Path Finder in Getting Data In 09-14-2010
1 2
1
2
devilears
How do I monitor how often my users are using Splunk?
by devilears New Member in Getting Data In 09-14-2010
0 1
0
1
Ant1D
Good Morning, I have a question that I would love to be answered if possible.  I have written the following xml c...
by Ant1D Motivator in Getting Data In 09-14-2010
0 11
0
11
melonman
Hi there, I would like to know how to handle international character code in Splunk. The environment I have here i...
by melonman Motivator in Getting Data In 09-14-2010
0 6
0
6
chjpcert
I've been testing Splunk for several months now, and am consistently having problems with duplicate events appearing ...
by chjpcert Explorer in Getting Data In 09-14-2010
1 8
1
8
rgcox1
So we know about lost forwarders, but how about lost logs? I recently discovered that some of my Windows systems were...
by rgcox1 Communicator in Getting Data In 09-13-2010
0 4
0
4
Nicholas_Key
Hi all, I have the following output from a Perl script that runs every 5 mins: 09-13-2010 16:21:20 - Inventory Rep...
by Nicholas_Key Splunk Employee Splunk Employee in Getting Data In 09-13-2010
1 2
1
2
SK110176
I'm noticed tons of duplicate events and the following message in splunkd.log correlates with the time I started seei...
by SK110176 Path Finder in Getting Data In 09-13-2010
1 1
1
1
Caio_Santos
Hey everybody, I'm going through some problems trying to set my receiver splunk instance. I performed exactely the w...
by Caio_Santos Path Finder in Getting Data In 09-13-2010
1 2
1
2
Genti
Folks, Im trying to troubleshoot an issue where syslog data seems to stop for a couple of days, then pick up again. ...
by Genti Splunk Employee Splunk Employee in Getting Data In 09-13-2010
1 6
1
6
skippylou
Going through other splunk answers questions I couldn't get anything that I think should be working to work here. Es...
by skippylou Communicator in Getting Data In 09-13-2010
0 8
0
8
cookdg
i downloaded the following logs to my workstation running xp and i have splunk running on it. how do i import them i...
by cookdg New Member in Getting Data In 09-13-2010
0 3
0
3
hiddenkirby
At a high level... how would one filter the content itself being indexed. Example: i was indexing ..say.. xml docs ...
by hiddenkirby Contributor in Getting Data In 09-13-2010
2 1
2
1
Dan
We are having an issue where we would like to route all events from a specific source to a third-party (ArcSight) but...
by Dan Splunk Employee Splunk Employee in Getting Data In 09-13-2010
1 1
1
1
briguy
Hi All - I'm using the WMI input to gather some custom WMI data. Some of the queries (such as below) result in duplic...
by briguy Engager in Getting Data In 09-13-2010
0 2
0
2
Erik_Swan
I remember reading somewhere i could do this but cannot find any docs on it. I have a scripted input that wants to p...
by Erik_Swan Splunk Employee Splunk Employee in Getting Data In 09-12-2010
2 4
2
4
fcastano
How do I force splunk to index new files in the directory that is being monitored immediately? sometimes it takes re...
by fcastano Engager in Getting Data In 09-11-2010
2 3
2
3
hulahoop
Would someone kindly confirm if Splunk is expected to preserve the order of events as they are presented in the origi...
by hulahoop Splunk Employee Splunk Employee in Getting Data In 09-10-2010
3 7
3
7
kmille2
Can the forwarding port be set to a UDP port? Tried changing the type to UDP in the outputs.conf file, but Splunk ke...
by kmille2 Explorer in Getting Data In 09-10-2010
1 2
1
2
mfrost8
I have a tree of files that looks something like the following: /var/log/able/access.log /var/log/baker/access.log /...
by mfrost8 Builder in Getting Data In 09-10-2010
0 8
0
8
kholleran
Hello, My splunk server belongs to a different domain with a trust set up. I have a python script that does some Ac...
by kholleran Communicator in Getting Data In 09-10-2010
0 7
0
7
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...
Top Solution Authors