Getting Data In

Getting Data In
Community Activity
jkamdar
Hi, I have a small lab (air gapped) with about 2 Linux servers  not including the Splunk server and 25 Windows machin...
by jkamdar Communicator in Getting Data In 04-25-2025
0 3
0
3
danielbb
We have a Splunk app that includes multiple scripted inputs.The app is deployed to 15 heavy forwarders, but we want o...
by danielbb Motivator in Getting Data In 04-25-2025
0 4
0
4
punkle64
I have the following source log files:[root@lts-reporting ~]# head /nfs/LTS/splunk/lts12_summary.log2014-07-01T00:00:...
by punkle64 Engager in Getting Data In 04-25-2025
0 11
0
11
hemant_lnu
We have one index os_linux which has 2 source type and i see props and transform is written .can you help me to under...
by hemant_lnu Engager in Getting Data In 04-24-2025
0 1
0
1
afx
The post question did include the answer, but then it could not be marked as an answer, therefore I pushed the conten...
by afx Contributor in Getting Data In 04-24-2025
3 28
3
28
fhatrick
Hi, I have created a new token and index in splunk for my mulesoft project.These are the configurations I have done i...
by fhatrick Loves-to-Learn in Getting Data In 04-24-2025
0 6
0
6
Karthikeya
We have installed Akamai add-on (https://splunkbase.splunk.com/app/4310) on our HF and installed Java and configured ...
by Karthikeya Communicator in Getting Data In 04-24-2025
0 2
0
2
davidco
We want to use splunk-library-javalogging to send logs via Log4j  to Splunk ServiceEnvironment: Spark with log4j2 in ...
by davidco Loves-to-Learn in Getting Data In 04-23-2025
0 5
0
5
ProPoPop
Hello team!We have a problem with sending data from several Domain Controllers to our splunk instance. We are collect...
by ProPoPop Loves-to-Learn Lots in Getting Data In 04-23-2025
0 2
0
2
gn694
Is there any way to tell whether data coming into Splunk's HEC was sent to the event or raw endpoint?You can't really...
by gn694 Communicator in Getting Data In 04-23-2025
0 4
0
4
Andre_
Hello,We have a few hundred hosts and a handful of customers. I have a csv file with serverName,customerID.I've been ...
by Andre_ Path Finder in Getting Data In 04-23-2025
0 2
0
2
becksyboy
Hi All,Has anyone managed to map CrowdStrike Falcon FileVantage (FIM) logs to a Datamodel; if so could you share your...
by becksyboy Contributor in Getting Data In 04-23-2025
0 3
0
3
Splunkers2
Hi, I have onboarded palo-alto traffic and threat logs via HEC and SLS (Strata logging service). These logs are JSON ...
by Splunkers2 Observer in Getting Data In 04-23-2025
0 1
0
1
danielbb
For multiple sourcetypes, linecount is 2, while clearly, it should be 1. Has anybody encountered this case?
by danielbb Motivator in Getting Data In 04-22-2025
0 8
0
8
BogeyMan
Not sure this is even possible, but I'll ask anyway...I have application(s) that are sending JSON data into Splunk, f...
by BogeyMan Loves-to-Learn Lots in Getting Data In 04-22-2025
0 1
0
1
ws
Hi,Unsure what is the root cause as i was trying to do some minor adjustment to ignore the [ ] at the transforms.conf...
by ws Path Finder in Getting Data In 04-22-2025
0 3
0
3
ws
Hi,I'm facing an issue where the same data gets indexed multiple times every time the JSON file is pulled from the FT...
by ws Path Finder in Getting Data In 04-22-2025
0 10
0
10
Mridu27
In earlier versions of splunk i remember there use to be an option to disable active user and it will then show as st...
by Mridu27 Engager in Getting Data In 04-22-2025
0 3
0
3
tech_g706
Hi,I need recommendations on typo3 logs source type.Be default, I set source type as "typo3" in inputs.conf but logs ...
by tech_g706 Path Finder in Getting Data In 04-21-2025
0 3
0
3
ws
I'm looking for a way to split a JSON array into multiple events, but it keeps getting indexed as a single event.I've...
by ws Path Finder in Getting Data In 04-21-2025
0 15
0
15
siddharth1479
Hi Community, I'm trying to extract search results using REST API and I'm facing the following problem. 1. I'm using...
by siddharth1479 Path Finder in Getting Data In 04-18-2025
1 11
1
11
Bobert
I've been writing new pipelines to my Edge Processors when I discovered that no destination values are showing up for...
by Bobert Observer in Getting Data In 04-18-2025
0 0
0
0
tangtangtang12
I've read through some of the Splunk documentation and previously one of my colleagues already configured the "Window...
by tangtangtang12 Loves-to-Learn Lots in Getting Data In 04-17-2025
0 2
0
2
Hemant_h
We have 40 dc server sending logs to onprem indexers but i see on Deployment server i can see only on App which has o...
by Hemant_h Engager in Getting Data In 04-17-2025
0 2
0
2
dionrivera
I have 40 Windows 2012 domain controllers (forwarding through heavy forwarders to cloud), that intermittently stop se...
by dionrivera Communicator in Getting Data In 04-17-2025
0 15
0
15
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...