Getting Data In

Getting Data In
Community Activity
AK_Splunk
How can I control or force the hostname to be a specific value via inputs.conf?Inputs.conf stanza[monitor:///var/log/...
by AK_Splunk Explorer in Getting Data In 03-30-2023
0 1
0
1
glpadilla_sol
Hello community, I have an issue with one forwarder, was working and suddenly stopped sending data to the Indexers. T...
by glpadilla_sol Path Finder in Getting Data In 03-29-2023
0 1
0
1
andrewtrobec
Hello!My objective is to put the license expiry on a dashboard.  I read some older posts that state I can call a REST...
by andrewtrobec Motivator in Getting Data In 03-29-2023
0 8
0
8
bapun18
Needs to blacklist certain syslogs messages from the forwarder level. We have raw syslogs as below:2023-03-27T00:00:0...
by bapun18 Communicator in Getting Data In 03-28-2023
0 3
0
3
mburgess97
How often do scripted inputs execute?  I want to implement some of these for exchange, but concerned that they will c...
by mburgess97 Path Finder in Getting Data In 03-28-2023
0 1
0
1
vishalduttauk
I've created fields from regex expressions before but never from the source field. This is an example of the value wi...
by vishalduttauk Communicator in Getting Data In 03-28-2023
0 2
0
2
AK_Splunk
Need help with regex for inputs.conf to change the host as hostname and incase host has FQDN it should pick up till h...
by AK_Splunk Explorer in Getting Data In 03-28-2023
0 6
0
6
newportknight
Hi, I am trying to get secure comms between a Forwarder and Indexer up and running using self signed certs but depite...
by newportknight Loves-to-Learn in Getting Data In 03-28-2023
0 1
0
1
NJ
Hi everyone. I have followed the documentation for setting up TLS for inter-Splunk communication with self-signed cer...
by NJ Path Finder in Getting Data In 03-28-2023
0 26
0
26
adelamora
My org has had a problem for awhile now where our Splunk logs pulled from SF are delayed between 1-2 hours. We are us...
by adelamora Observer in Getting Data In 03-28-2023
0 1
0
1
gots
We have an index with access logs from multiple hosts and systems with different sourcetypes. When I trying to add in...
by gots Path Finder in Getting Data In 03-28-2023
1 5
1
5
domino30
I am in a environment and I am able to get data in from a general perspective. We have a index clustered and search h...
by domino30 Path Finder in Getting Data In 03-27-2023
0 4
0
4
domino30
We have a Search Head clustered and Indexer Clustered env. we have a deployers which is not a SH or and Indexer just ...
by domino30 Path Finder in Getting Data In 03-27-2023
0 1
0
1
NanSplk01
I have been trying to create this sourcetype and am not sure I'm capturing it correctly.     Sample date:      [2023-...
by NanSplk01 Communicator in Getting Data In 03-27-2023
0 1
0
1
aaron_francis
Hello, Newish to splunk here. We have an AWX instance (free Tower) and we are trying to send the logs to splunk using...
by aaron_francis New Member in Getting Data In 03-27-2023
0 0
0
0
VK18
Hi Team. I'm looking for a way to rename a correlation search that has been created with the wrong format. The CS is ...
by VK18 Explorer in Getting Data In 03-27-2023
0 4
0
4
Mels
I'm posting a json struct such as        { "index": "test_metrics", "time": 1679920906.0, "event": "metric", ...
by Mels Engager in Getting Data In 03-27-2023
1 0
1
0
JohnDuatres
Hello, teamI've made script, which uses the sudo command. I've deployed it on my forwarders, and I get the error:mess...
by JohnDuatres Explorer in Getting Data In 03-27-2023
0 5
0
5
vishalduttauk
Hi all, I am getting data in via an API (using the add on builder) but having  creating a regex which splits it into ...
by vishalduttauk Communicator in Getting Data In 03-27-2023
0 2
0
2
Charlize
Hi,My single event length is too long so I want to extract and ingest the specific part from it. The part is in the m...
by Charlize Engager in Getting Data In 03-27-2023
0 1
0
1
JGP
We want to set default TZ as SGT for a particular Search Head and that SH is in EDT TZ. We have already applied TZ se...
by JGP Explorer in Getting Data In 03-27-2023
0 13
0
13
andrewwhitlock
I am looking for a Splunk query that will pull the enabled and disabled ciphers from windows servers in my environmen...
by andrewwhitlock New Member in Getting Data In 03-24-2023
0 0
0
0
aasabatini
Hi folks, I have a field alias for my all sourcetypes        [default] FIELDALIAS-cliente = index AS client         b...
by aasabatini Motivator in Getting Data In 03-24-2023
0 9
0
9
umesh
Hi Everyone,   I recently observed the splunk internal logs and found that there is a field component and found two v...
by umesh Path Finder in Getting Data In 03-24-2023
0 1
0
1
bitnapper
Hi, I took over a Splunk Cluster with Splunk on c:\program files\splunk which produces plenty of problems due to long...
by bitnapper Path Finder in Getting Data In 03-24-2023
0 3
0
3
Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...
Top Solution Authors