Getting Data In

Getting Data In
Community Activity
Fares_Hossam
How can I configure my F5 BIG-IP to forward logs from a load-balanced server pool to Splunk?
by Fares_Hossam Engager in Getting Data In 09-16-2025
0 1
0
1
utoddl
I have a not-very-complicated query that returns a table of my roles and associated default search indexes. One role ...
by utoddl Explorer in Getting Data In 09-15-2025
0 1
0
1
davidoff96
Hello,We're currently having an issue of SC4S tagging Cisco firepower data as nix:syslog, but I was having this issue...
by davidoff96 Path Finder in Getting Data In 09-15-2025
0 2
0
2
lucacaldiero
Hello,I wanna forward all data from a single HF to two splunk different instances. How can i do that? Thanks #splunk ...
by lucacaldiero Path Finder in Getting Data In 09-15-2025
0 10
0
10
lucacaldiero
How can I specify all host or sources in a stanza of props.conf?Thank you @gcusello 
by lucacaldiero Path Finder in Getting Data In 09-15-2025
0 3
0
3
vincentwhn
Due to privacy concerns, I would like to modify the _raw content during the data onboarding phase in order to impleme...
by vincentwhn Engager in Getting Data In 09-15-2025
0 7
0
7
Ghostoverflow25
I have a source of logs that I want to ingest into splunk, where each line documents a seperate event. After having s...
by Ghostoverflow25 Engager in Getting Data In 09-14-2025
0 1
0
1
jackbenimble
What would it take to use something like REST API to pull down documents from Splunk Documentation website? The searc...
by jackbenimble New Member in Getting Data In 09-12-2025
0 1
0
1
hrawat
Apply following workaround in default-mode.confAdditionally you can also push this change via DS push across thousand...
by hrawat Splunk Employee Splunk Employee in Getting Data In 09-12-2025
4 17
4
17
JyPl4wNYu7GV1uL
CentOS 7.7.1908, Splunk  v9.1.0.2I want to get an example event for each sourcetype on each host (excluding one host)...
by JyPl4wNYu7GV1uL Explorer in Getting Data In 09-12-2025
0 4
0
4
kumva01
Hi All,I’m looking for an SPL query that can return the list of Tag Names along with their associated field-value pai...
by kumva01 Loves-to-Learn Lots in Getting Data In 09-12-2025
0 2
0
2
taskmaster
I'm new to Splunk... I'm currently running Splunk on an Ubuntu system.  I've noticed that the /proc directory is show...
by taskmaster Engager in Getting Data In 09-12-2025
0 4
0
4
Nrsch
Hi, I am installing Splunk UBA 5.4.2 on my laptop in a virtual machine (RHEL 8.8) for testing. I followed the install...
by Nrsch Explorer in Getting Data In 09-10-2025
0 2
0
2
L_Petch
Hello, I am trying to get logs from my opnsense FW to go to an index called prod_opnsense but everything I have tried...
by L_Petch Path Finder in Getting Data In 09-10-2025
0 1
0
1
rk99
Hi - we have been sending data from our K8s cluster to splunk hwf which then forwards to the indexer.  It works great...
by rk99 Explorer in Getting Data In 09-10-2025
0 3
0
3
kramer0101
We are looking at bringing in Semperis DSP logs to evaluate them. Is there documentation on sending those logs to Spl...
by kramer0101 Engager in Getting Data In 09-09-2025
0 2
0
2
d_lim
Are we able to ingest into Splunk the config change events such as the attached image, using "Proofpoint On Demand Em...
by d_lim Path Finder in Getting Data In 09-09-2025
0 1
0
1
gcusello
Hi at all,I have to parse Juniper Switch logs that are very similar to Cisco ios.In the Juniper Add-On there isn't an...
by SplunkTrust SplunkTrust in Getting Data In 09-09-2025
0 4
0
4
sirisha
I’m currently instrumenting a .NET application to send telemetry to Splunk Observability Cloud using the Splunk Distr...
by sirisha New Member in Getting Data In 09-09-2025
0 0
0
0
Na_Kang_Lim
Hi,I am configure the apps on the UF from a Deploy Server, and get this weird behavior:What I am trying to do is assi...
by Na_Kang_Lim Path Finder in Getting Data In 09-08-2025
0 3
0
3
gsiebert
Environment- Splunk Enterprise 10.0.0 (Ubuntu 24.04), single VM (indexer+SH+Stream)- splunk_app_stream 8.1.5, Splunk_...
by gsiebert New Member in Getting Data In 09-08-2025
0 0
0
0
karol
I got my data stream in a following format:[ { "name": "event 1" "attributes": [false, true, true...
by karol Engager in Getting Data In 09-07-2025
0 1
0
1
_Raj
Hi,I want to install the BOTS v3 dataset on Splunk 10.0 in Windows OS. Is it compatible with this version? If yes, ho...
by _Raj Path Finder in Getting Data In 09-06-2025
0 2
0
2
Raghavsri
we have one HF , configured to routing into 3 destinations 2 * syslogNG1* Splunk HF clusterour requirement is to drop...
by Raghavsri Loves-to-Learn Lots in Getting Data In 09-04-2025
0 2
0
2
umd06
 I’m trying to split my Windows events so that:All events get forwarded to a syslog server.Only certain Event IDs (ex...
by umd06 Engager in Getting Data In 09-04-2025
0 2
0
2
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...
Top Solution Authors