| Thread Info | |||||
|---|---|---|---|---|---|
|
Hello Splunkers,I have a small question, what is the best practice (or for what reasons) should I use Syslog or TCP c...
by
GaetanVP
Contributor
in
Getting Data In
10-03-2022
|
0
|
8
| |||
|
Hello, I am new to the Splunk interface and I have been recently given a task to configure Splunk to monitor the foll...
by
sgutierrez
Engager
in
Getting Data In
06-17-2019
|
1
|
4
| |||
|
I ma trying to onboard the %SystemRoot%\System32\Winevt\Logs\Microsoft-AzureADPasswordProtection-DCAgent%4Admin.evtx ...
by
Dilsheer_P
Loves-to-Learn Lots
in
Getting Data In
12-26-2024
|
0
|
2
| |||
|
I have the following transforms.conf file:
[pan_src_user]INGEST_EVAL=src_user_idx=json_extract(lookup("user_ip_mapp...
by
Niro
Explorer
in
Getting Data In
01-03-2024
|
0
|
10
| |||
|
I need to use federated search which does not support search time lookup at this time in splunk 8.2.2.1.
I came acr...
by
patelmc
Explorer
in
Getting Data In
11-08-2021
|
0
|
2
| |||
|
I have syslog events being written to a HF locally via syslog-ng - these events are then consumed via file reader and...
by
Skins
Path Finder
in
Getting Data In
02-18-2024
|
0
|
3
| |||
|
Brand new to splunk, inherited a slightly configured system.
I want to move certain cribl events to an index called...
by
dtamburin
Engager
in
Getting Data In
05-13-2025
|
0
|
3
| |||
|
i have used this approach to forward logs from specific index to third-party system in my case Qradar
so i need...
by
KhalidAlharthi
Explorer
in
Getting Data In
06-09-2024
|
0
|
10
| |||
|
I've a few different automated pulls of data into directories of files I want splunk to index. These files get comple...
by
mjones414
Contributor
in
Getting Data In
03-29-2019
|
1
|
16
| |||
|
Hi all,
I'm struggling with an issue related to collecting Fortinet Fortios events through SC4S. If I use UDP proto...
by
Numb78
Explorer
in
Getting Data In
05-07-2025
|
0
|
3
| |||
|
I was trying to download the universal forwarder for windows 7 32 bit OS, but i can see only windows 8, 8.1, 10 OS. ...
by
twh1
Communicator
in
Getting Data In
04-01-2017
|
0
|
9
| |||
|
I'm attempting to set up an Independent Stream Forwarder on a RHEL machine to collect netflow data, and have it forwa...
by
Mit
Observer
in
Getting Data In
05-08-2025
|
0
|
1
| |||
|
Dear Splunk Community,
I am currently working on a project focused on identifying the essential data that should be...
by
kn450
Explorer
in
Getting Data In
05-10-2025
|
0
|
6
| |||
|
We've logs coming to HEC as nested JSON in chunks; We're trying to break them down into individual events at the HEC ...
by
nmohammed
Builder
in
Getting Data In
05-01-2025
|
0
|
12
| |||
|
Hi Folks,New to Splunk and SC4S deploymenet. So far I have been able to make good progress. I have setup 2 SC4S serve...
by
capjacksparo
Engager
in
Getting Data In
04-20-2025
|
0
|
5
| |||
|
Response Code: 401Response text: <?xml version="1.0" encoding="UTF-8"?><response><messages><msg type="WARN">call not ...
by
NatanS
Explorer
in
Getting Data In
08-17-2024
|
1
|
8
| |||
|
I have this kind of weird custom app (and dangerous too) that changes the UF Instance GUID. Basically, I created a ....
by
Na_Kang_Lim
Path Finder
in
Getting Data In
05-06-2025
|
0
|
1
| |||
|
I'm running into a strange issue where Splunk is using the current time for a HTTP Event Collector input rather than ...
by
Kieffer87
Communicator
in
Getting Data In
01-18-2019
|
1
|
10
| |||
|
Hello Splunk Community!
Welcome to the first post of the Splunk Answers Content Calendar
This week, I'll...
by
Anam
Community Manager
in
Getting Data In
05-06-2025
|
2
|
0
| |||
|
2025-05-06T13:50:00.857Z error helper/transformer.go:118 Failed to process entry {"otelcol.component.id": "filelog", ...
by
tawfiq15
New Member
in
Getting Data In
05-06-2025
|
0
|
1
| |||
|
Hi splunk community, I have a question on logs cloning/redirection
Purpose :
Extract logs containing "network-gue...
by
Nicolas2203
Path Finder
in
Getting Data In
04-17-2025
|
0
|
19
| |||
|
Hi,
After setting up a test index and ingesting a test record, I’m now planning to remove the index from the distri...
by
ws
Path Finder
in
Getting Data In
05-04-2025
|
0
|
3
| |||
|
How to onboard MOVEit Server Database logs which is hosted on prem to Splunk Cloud? What is the preferred method?
by
msatish
Path Finder
in
Getting Data In
05-05-2025
|
0
|
1
| |||
|
Hi,We have db connect connections & inputs created in Splunk HF. We see that it has status=FAILED sometimes and below...
by
juhiacc
Explorer
in
Getting Data In
05-02-2025
|
0
|
3
| |||
|
We have a universal forwarder and the customer has a csv file on this machine that he would like to ingest. The custo...
by
danielbb
Motivator
in
Getting Data In
05-02-2025
|
0
|
2
|