Getting Data In

Getting Data In
Community Activity
Yancy
Is there a way to set tags based off a wild card value? IE I have the following hosts and I want to apply the 'test'...
by Yancy Path Finder in Getting Data In 05-27-2010
0 2
0
2
msenthilganesh
I am expecting to see each record as an event, but the result is not as expected. Some records are displayed as indi...
by msenthilganesh New Member in Getting Data In 05-26-2010
0 1
0
1
Chris_R_
If we have an indexer configured w/a raid 5 or raid 6 array is this going to negatively affect performance?
by Chris_R_ Splunk Employee Splunk Employee in Getting Data In 05-26-2010
2 4
2
4
littlejef
I am currently running a eval version of Splunk 4.0.9 on a Windows 2008 64Bit Host. Our purchase of Splunk has been a...
by littlejef Engager in Getting Data In 05-26-2010
1 1
1
1
balbano
Hi, we are currently testing a Palo Alto app sec firewall and are sending some test logs over to the central indexer ...
by balbano Contributor in Getting Data In 05-26-2010
0 6
0
6
Genti
I would like to deploy Light Forwarders at our remote locations to act as a syslog server. Can light forwarder be con...
by Genti Splunk Employee Splunk Employee in Getting Data In 05-25-2010
2 2
2
2
wdc
I've found how to get data from a remote users Security Log but we are after a centralised area to keep these logs. I...
by wdc New Member in Getting Data In 05-25-2010
0 3
0
3
ASW3382
I am revisiting splunk to see if it will meet our goals. Right now I am working on the initial index of our data gat...
by ASW3382 New Member in Getting Data In 05-24-2010
0 4
0
4
Jaci
Our indexer and all forwarders are running 4.1.2. Recently we developed a need to send events from our forwarders in...
by Jaci Splunk Employee Splunk Employee in Getting Data In 05-24-2010
1 3
1
3
Genti
What is the relationship between size of logs received by Splunk indexing servers versus indexing volume? On the load...
by Genti Splunk Employee Splunk Employee in Getting Data In 05-24-2010
0 1
0
1
Jaci
I have a deployment server app with a single inputs.conf file. [tcp://localhost:9997] sourcetype = tcp-raw index = p...
by Jaci Splunk Employee Splunk Employee in Getting Data In 05-24-2010
1 2
1
2
jeff
I have the following in inputs.conf: [udp://32004] host = custom_host connection_host = non...
by jeff Contributor in Getting Data In 05-22-2010
3 3
3
3
mctester
Hi, I have a development support question. We have an application that is integrated with splunk. We have a C++ p...
by mctester Communicator in Getting Data In 05-22-2010
2 1
2
1
dcroteau
we only want to save the log info for 2 weeks. I tried to set this up by modifying the frozen time, but it doesn’t s...
by dcroteau Splunk Employee Splunk Employee in Getting Data In 05-22-2010
1 3
1
3
maverick
Suppose I splunk a file and it is gzip'd on disk under the appropriate Splunk index directory. Then let's say I con...
by maverick Splunk Employee Splunk Employee in Getting Data In 05-22-2010
1 1
1
1
Genti
Forwarding a question: "... attempting to setup a lookup table. Each time I save an automatic lookup it always retur...
by Genti Splunk Employee Splunk Employee in Getting Data In 05-21-2010
0 1
0
1
Justin_Grant
If our app's inputs.conf uses an index other than "main" (e.g. a custom index for our app) does our app's setup UI (o...
by Justin_Grant Contributor in Getting Data In 05-21-2010
1 5
1
5
Jaci
Does a forwarder keep using the initial TCP connection to the indexing server, or does it close the connection after ...
by Jaci Splunk Employee Splunk Employee in Getting Data In 05-21-2010
2 1
2
1
return2health
Hi there. I'm new to splunk. Having a bit of trouble getting my head around it ( I know SQL well ) . I want to get...
by return2health Engager in Getting Data In 05-21-2010
1 2
1
2
Nicholas_Key
I am perplexed with what I'm experiencing right now. I have all the file inputs enabled for monitor but I'm not seei...
by Nicholas_Key Splunk Employee Splunk Employee in Getting Data In 05-21-2010
1 2
1
2
Jaci
I monitor a log file (access_log) that gets rolled every night at 1 am using a copy command "cp /dev/null access_toda...
by Jaci Splunk Employee Splunk Employee in Getting Data In 05-20-2010
1 3
1
3
jwestberg
I am creating an app for Splunk 4.1 that has a scripted input that retrieves data from a database. At first run, it w...
by jwestberg Splunk Employee Splunk Employee in Getting Data In 05-20-2010
2 5
2
5
phoenixsecure
Hi, I am collecting event logs thru WMI for Windows 2000 and 2003 servers, for 2003 everything seem ok but for 2000 ...
by phoenixsecure Engager in Getting Data In 05-20-2010
2 2
2
2
Chris_R_
How do keep splunk from removing syslog priority fields? They are removed once indexed into splunk.
by Chris_R_ Splunk Employee Splunk Employee in Getting Data In 05-19-2010
0 3
0
3
Yancy
Since I updated our server to 4.1.2 I'm seeing the following error with most searches. The lookup table 'sid_look...
by Yancy Path Finder in Getting Data In 05-19-2010
2 2
2
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...