Getting Data In

Getting Data In
Community Activity
sigma
Hi all,I want to extract fields from a custom log format. Here's my transforms.conf:REGEX = ^\w+\s+\d+\s+\d+:\d+:\d+\...
by sigma Path Finder in Getting Data In 07-29-2025
0 2
0
2
KwonTaeHoon
HelloI'm collecting cloudtrail logs by installing Splunk add on AWS in the Splunk heavy forwarder.The following logs ...
by KwonTaeHoon Path Finder in Getting Data In 07-28-2025
0 1
0
1
sigma
Hi all,I'm collecting iLO logs in Splunk and have set up configurations on a Heavy Forwarder (HF). Logs are correctly...
by sigma Path Finder in Getting Data In 07-28-2025
0 5
0
5
shoaibalimir
Hi Community,I'm exploring ways to ingest data into Splunk Cloud from a Amazon s3 Bucket which has multiple directori...
by shoaibalimir Path Finder in Getting Data In 07-28-2025
0 2
0
2
n_hoh
Hi All I've been tasked with setting up logging for Windows Certification Services and getting this into Splunk.Have ...
by n_hoh Observer in Getting Data In 07-28-2025
0 6
0
6
verbal_666
Hi.During the day, some on my Indexers completely stops sending back the ACK, so many agents keep data in queue until...
by verbal_666 Builder in Getting Data In 07-26-2025
0 6
0
6
isahu
I onboarded one production logs to splunk but after restarting the UF I am not able to see the recent logs also I am ...
by isahu Observer in Getting Data In 07-26-2025
0 3
0
3
samalchow
I’ve inherited a fleet of about 150 Windows Servers, all configured identically — same Deployment Server, TAs, inputs...
by samalchow Observer in Getting Data In 07-25-2025
0 6
0
6
jbanAtSplunk
Hi,Does anyone have a good example from Logstash to Splunk HEC?I only get "services/collector/raw" working with logst...
by jbanAtSplunk Communicator in Getting Data In 07-24-2025
0 18
0
18
zaks191
Hi Splunk Community,I'm new to Splunk and working on a deployment where we index large volumes of data (approximately...
by zaks191 New Member in Getting Data In 07-24-2025
0 5
0
5
nopera
Hi,Could you help me retrieve message-tracking logs from our on-premises Exchange server? I added the following lines...
by nopera Explorer in Getting Data In 07-22-2025
0 11
0
11
dsgoody
Hi all,I'm having some issues excluding events from our Juniper SRX logs. These events are ingested directly on our W...
by dsgoody Engager in Getting Data In 07-22-2025
0 2
0
2
verbal_666
Hello.I'm actually using aparallelIngestionPipelines = 2feature on my Indexers. Works.Servers (Linux) are professiona...
by verbal_666 Builder in Getting Data In 07-22-2025
0 5
0
5
LS1
LS1_0-1752859704846.png  LS1_2-1752859759798.png Hello, maybe I don't have the vocabulary to find the answer when Goo...
by LS1 Loves-to-Learn Lots in Getting Data In 07-21-2025
0 12
0
12
palyogit
http event data is not received at index though in the log it says HttpInputDataHandler - handled token name=xyz How ...
by palyogit New Member in Getting Data In 07-20-2025
0 5
0
5
vulnfree
Hi Splunkers,I'm having issues ingesting Windows DNS Server Analytical logs. What's strange is that I am able to pull...
by vulnfree Explorer in Getting Data In 07-18-2025
0 1
0
1
BoscoBaracus
Good morning All,I have been trying to figure out how can I create a data input on a heavy forwarder to forward data ...
by BoscoBaracus Engager in Getting Data In 07-18-2025
0 12
0
12
ez-secops-awn
I would greatly appreciate support for customer model as a correlation search option in the VT4splunk app.
by ez-secops-awn Engager in Getting Data In 07-17-2025
0 5
0
5
MatheoCaneva1
Hi everyone!Quick question. I would like to know how can I send data to an index using a python script.We need to ing...
by MatheoCaneva1 Engager in Getting Data In 07-17-2025
0 6
0
6
dm1
I need to onboard Cisco Catalyst 8500 router logs into Splunk. When I was looking for addons, I found the below addon...
by dm1 Builder in Getting Data In 07-16-2025
0 1
0
1
Cheng2Ready
[monitor://\\njros1bva0597\d$\LogFiles\warcraft-9.0.71\logs\*] disabled = false host = NJROS1BVA0621 alwaysOpenFile =...
by Cheng2Ready Communicator in Getting Data In 07-16-2025
0 6
0
6
tbarn005
Trying to filter out all perfmon data using ingest actions. so, i try and see the samples and i get this error tbarn0...
by tbarn005 Engager in Getting Data In 07-16-2025
0 7
0
7
asah
Hi Splunk Gurus, I’m working on a script to programmatically check if logs from a specific host are available in Splu...
by asah Engager in Getting Data In 07-16-2025
0 2
0
2
sudha_krish
I'm cloning the event and before cloning  extracting sourcetype to use later.transforms.conf [copy_original_sourcety...
by sudha_krish Explorer in Getting Data In 07-16-2025
0 5
0
5
elend
Currently I have setup Splunkstream, but there is a condition where I want to disable some data sources from certain ...
by elend Communicator in Getting Data In 07-15-2025
0 4
0
4
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors