Getting Data In

Getting Data In
Community Activity
shashilendra
Hi Team, getting huges audit logs and wanted to blacklist in input.conf  . index=*linux* source="/var/log/audit/audit...
by shashilendra Explorer in Getting Data In 12-27-2022
0 5
0
5
sekhar463
Good day, i am using search query to correlate one field belongs and related jobs for that field i am using below que...
by sekhar463 Path Finder in Getting Data In 12-26-2022
0 1
0
1
sloshburch
I've heard that using Splunk's default source type detection is flexible, but can be hard on performance. What is the...
by sloshburch Ultra Champion in Getting Data In 12-25-2022
0 17
0
17
m_zandinia
Hi, I collected the cisco deviceslog with "Cisco Networks Add-on for Splunk Enterprise". And install  "Cisco Networks...
by m_zandinia Path Finder in Getting Data In 12-24-2022
0 0
0
0
bhsakarchourasi
Hi All,We are working in Splunk Cloud environment, I want to deploy custom the TIME_PREFIX configuration for one of t...
by bhsakarchourasi Path Finder in Getting Data In 12-23-2022
0 2
0
2
mdtoro
I have a case where some indexers take 4 to 5 hours to join the cluster. The system shows no/little system usage (CP...
by mdtoro Explorer in Getting Data In 12-23-2022
0 3
0
3
Roy_9
I have setup servicenow to splunk integration and coming to the inputs, I have turned on  the Splunk sys user group a...
by Roy_9 Motivator in Getting Data In 12-23-2022
0 0
0
0
bosseres
Hello, everyoneI've "all-in-one" splunk installation, configured syslog input, but input messages are rejected.Below ...
by bosseres Contributor in Getting Data In 12-23-2022
1 1
1
1
divya_gn1
There is a threat log with 2 sub_types (url and vulnerability) and sample data are as below.panwlogs-,2022-12-15T08:4...
by divya_gn1 Loves-to-Learn in Getting Data In 12-23-2022
0 0
0
0
hectorvp
I just installed universal forwarder, And was deploying my first app using DS, I came accros few apps in place prior ...
by hectorvp Communicator in Getting Data In 12-22-2022
0 5
0
5
davidwaugh
Hello i have two windows event collectors. 3 domain controllers send their events to one event collector (WEC01), and...
by davidwaugh Path Finder in Getting Data In 12-22-2022
2 25
2
25
calvinmcelroy
We have a distributed splunk (8.x) environment on-prem, with CM and 3 peers, 2 SH, 1 deployment server, and many clie...
by calvinmcelroy Path Finder in Getting Data In 12-22-2022
0 3
0
3
dorbi
Hey there! I'm trying to monitor(batch)) a folder congaing  xml files,  the XML files don't necessarily have the same...
by dorbi Explorer in Getting Data In 12-22-2022
0 5
0
5
russell120k
Context: I have an external client that uses Arctic Wolf for sysmon logs on their endpoints and need to ingest those ...
by russell120k Engager in Getting Data In 12-22-2022
0 2
0
2
gsiuv
Disponemos de Splunk Cloud Victoria 9.0.2208.4 y hemos instalado y configurado: - Seguridad en la nube de Cisco  - Co...
by gsiuv Loves-to-Learn Lots in Getting Data In 12-22-2022
0 7
0
7
Pavan0604
Hi guys,  We need to get events generated from aws eventbridge to get into splunk. So we tried integrating the eventb...
by Pavan0604 Loves-to-Learn in Getting Data In 12-22-2022
0 0
0
0
ehudb
We have a new Splunk Cloud environment We are using AWS TA Add On to ingest files from S3 The files have extension of...
by ehudb Contributor in Getting Data In 12-21-2022
0 1
0
1
Johnsonbc
I am trying to create an after hour query with specific time frames 1. Mon 0000-0700 and 1900-2400, 2. Tue 0000-0700 ...
by Johnsonbc Explorer in Getting Data In 12-21-2022
0 5
0
5
GaetanVP
Hello Splunkers,I am currently having parsing problems with my Splunk Heavy Forwarder.I know I have heavy regex  that...
by GaetanVP Contributor in Getting Data In 12-21-2022
0 1
0
1
debjit_k
Hi , After onboarding trendmicro XDR we are facing few issue.  1. Getting logs in JSON format  2. Data is not pursed....
by debjit_k Path Finder in Getting Data In 12-20-2022
0 5
0
5
stwong
Hi all, I use following simple props.conf to some json type events: [my:sourcetype]category = StructuredDATETIME_CONF...
by stwong Communicator in Getting Data In 12-20-2022
0 3
0
3
alex4
I am getting logs in Splunk. But the logs are in improper format. So I want to make changes so that all my logs shoul...
by alex4 Loves-to-Learn Lots in Getting Data In 12-20-2022
0 2
0
2
sindhuja
Hi All,   I have integrated Splunk HEC with springboot .when i hit application and checked in splunk am unable to see...
by sindhuja Loves-to-Learn Lots in Getting Data In 12-20-2022
0 0
0
0
aa70627
Can someone assist with providing a working example on how to use and send data to Splunk HTTP Event Collect (HEC) fr...
by aa70627 Communicator in Getting Data In 12-20-2022
1 5
1
5
igor04653
Hello dear community Could you please tell me how to find the reason. I am using HTTP Event Collector for Kubernetes....
by igor04653 Loves-to-Learn Everything in Getting Data In 12-20-2022
0 1
0
1
Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...
Top Solution Authors