Getting Data In

Getting Data In
Community Activity
Chris_R_
Is there any way to check for forwarders that have not connected recently and include a "sourcetype, source or host" ...
by Chris_R_ Splunk Employee Splunk Employee in Getting Data In 05-28-2010
0 1
0
1
hiddenkirby
I have a dir of text files named like such scriptcalled_201005211317_stdout.txt how do i index them on that date...
by hiddenkirby Contributor in Getting Data In 05-27-2010
0 8
0
8
Lowell
I have a saved search that notifies me when a forwarder goes up or down based on various TcpInputProc and TcpOutputPr...
by Lowell Super Champion in Getting Data In 05-27-2010
4 1
4
1
scornish
All, I noticed discussions on how to prevent Splunk from stripping priority levels from UDP Syslog messages. Will pr...
by scornish Engager in Getting Data In 05-27-2010
3 1
3
1
ubko
Is there a way to pass the result of a savedsearch to a script? For example, if the search returns: suser duser ...
by ubko Explorer in Getting Data In 05-27-2010
2 2
2
2
sdwilkerson
Some events flow into the Splunk instance via syslog sockets. For a brief period of time, the sourcetypes that came ...
by sdwilkerson Contributor in Getting Data In 05-27-2010
1 3
1
3
lyndac
I have a .csv file that I'm indexing. There is no timestamp information in the .csv file, but there is a date in the...
by lyndac Contributor in Getting Data In 05-27-2010
2 5
2
5
hiddenkirby
strptime() format expression examples Below are some sample date formats with strptime() expressions that handle the...
by hiddenkirby Contributor in Getting Data In 05-27-2010
0 8
0
8
parallaxed
Splunk always seems to get this wrong. I have the following in a vain effort to correct this TIME_PREFIX=^ TIME_FOR...
by parallaxed Path Finder in Getting Data In 05-27-2010
2 10
2
10
Yancy
Is there a way to set tags based off a wild card value? IE I have the following hosts and I want to apply the 'test'...
by Yancy Path Finder in Getting Data In 05-27-2010
0 2
0
2
msenthilganesh
I am expecting to see each record as an event, but the result is not as expected. Some records are displayed as indi...
by msenthilganesh New Member in Getting Data In 05-26-2010
0 1
0
1
Chris_R_
If we have an indexer configured w/a raid 5 or raid 6 array is this going to negatively affect performance?
by Chris_R_ Splunk Employee Splunk Employee in Getting Data In 05-26-2010
2 4
2
4
littlejef
I am currently running a eval version of Splunk 4.0.9 on a Windows 2008 64Bit Host. Our purchase of Splunk has been a...
by littlejef Engager in Getting Data In 05-26-2010
1 1
1
1
balbano
Hi, we are currently testing a Palo Alto app sec firewall and are sending some test logs over to the central indexer ...
by balbano Contributor in Getting Data In 05-26-2010
0 6
0
6
Genti
I would like to deploy Light Forwarders at our remote locations to act as a syslog server. Can light forwarder be con...
by Genti Splunk Employee Splunk Employee in Getting Data In 05-25-2010
2 2
2
2
wdc
I've found how to get data from a remote users Security Log but we are after a centralised area to keep these logs. I...
by wdc New Member in Getting Data In 05-25-2010
0 3
0
3
ASW3382
I am revisiting splunk to see if it will meet our goals. Right now I am working on the initial index of our data gat...
by ASW3382 New Member in Getting Data In 05-24-2010
0 4
0
4
Jaci
Our indexer and all forwarders are running 4.1.2. Recently we developed a need to send events from our forwarders in...
by Jaci Splunk Employee Splunk Employee in Getting Data In 05-24-2010
1 3
1
3
Genti
What is the relationship between size of logs received by Splunk indexing servers versus indexing volume? On the load...
by Genti Splunk Employee Splunk Employee in Getting Data In 05-24-2010
0 1
0
1
Jaci
I have a deployment server app with a single inputs.conf file. [tcp://localhost:9997] sourcetype = tcp-raw index = p...
by Jaci Splunk Employee Splunk Employee in Getting Data In 05-24-2010
1 2
1
2
jeff
I have the following in inputs.conf: [udp://32004] host = custom_host connection_host = non...
by jeff Contributor in Getting Data In 05-22-2010
3 3
3
3
mctester
Hi, I have a development support question. We have an application that is integrated with splunk. We have a C++ p...
by mctester Communicator in Getting Data In 05-22-2010
2 1
2
1
dcroteau
we only want to save the log info for 2 weeks. I tried to set this up by modifying the frozen time, but it doesn’t s...
by dcroteau Splunk Employee Splunk Employee in Getting Data In 05-22-2010
1 3
1
3
maverick
Suppose I splunk a file and it is gzip'd on disk under the appropriate Splunk index directory. Then let's say I con...
by maverick Splunk Employee Splunk Employee in Getting Data In 05-22-2010
1 1
1
1
Genti
Forwarding a question: "... attempting to setup a lookup table. Each time I save an automatic lookup it always retur...
by Genti Splunk Employee Splunk Employee in Getting Data In 05-21-2010
0 1
0
1
Get Updates on the Splunk Community!

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...

What’s New in Splunk Observability Cloud: January Feature Highlights & Deep Dives

Splunk Observability Cloud continues to evolve, empowering engineering and operations teams with advanced ...
Top Solution Authors